A path traversal vulnerability exists where an attacker with access to manipulate inputs when initializing the Measured::Cache::Json class would be able to instruct the library to read arbitrary files.
Users should update to the latest version.
{
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-07-15T15:35:37Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-22"
]
}