CVE-2025-32961

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2025-32961 is a vulnerability affecting the Cuba JPA web API before version 1.1.1. Maliciously named files, which include an .html extension, can trick the API into returning a text/html Content-Type response. This could lead to the execution of malicious JavaScript code in the user's browser. A successful attack relies on an attacker uploading a malicious file first. This issue has been mitigated with the release of version 1.1.1. Users can also refer to the workaround provided on the Jmix documentation website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share