CVE-2025-29932
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 611
Summary
CVE-2025-29932 is a vulnerability affecting JetBrains GoLand before version 2025.1. This issue permits XML External Entity (XXE) attacks during debugging, which could lead to unintended data leakage or even remote code execution. Attackers could exploit this vulnerability by injecting malicious XML entities into debugging configuration files, potentially gaining unauthorized access to sensitive data or executing arbitrary code. Users are strongly advised to update their GoLand software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- JetBrains Goland
Affected Vendors
- JetBrains