CVE-2025-32961
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 79
Summary
CVE-2025-32961 is a vulnerability affecting the Cuba JPA web API before version 1.1.1. Maliciously named files, which include an .html extension, can trick the API into returning a text/html Content-Type response. This could lead to the execution of malicious JavaScript code in the user's browser. A successful attack relies on an attacker uploading a malicious file first. This issue has been mitigated with the release of version 1.1.1. Users can also refer to the workaround provided on the Jmix documentation website.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.