Third-Party Package Updates in Splunk SOAR - November 2025

Advisory ID: SVD-2025-1104

CVE ID:  Multiple

Published: 2025-11-26

Last Update: 2025-11-26

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk SOAR version 7.0.0, and higher.

PackageRemediationCVESeverity
setuptools1UpgradedCVE-2025-47273High
Jinja22UpgradedCVE-2024-56326Medium
@bable/helpers3UpgradedCVE-2025-27789Medium
@bable/runtime4UpgradedCVE-2025-27789Medium

1 Upgraded setuptools to 78.1.1 to remediate CVE-2025-47273

2 Upgraded Jinja2 to 3.1.6 to remediate CVE-2024-56326

3 Upgraded @bable/helpers to 7.26.10 to remediate CVE-2025-27789

4 Upgraded @bable/runtime to 7.26.10 to remediate CVE-2025-27789

Solution

Upgrade Splunk SOAR to version 7.0.0 or higher.

Splunk is actively monitoring and patching Splunk Cloud Platform instances.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk SOAR7.0Below 7.0.07.0.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.