CVE-2025-3804

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 476

Summary

CVE-2025-3804 is a critical vulnerability affecting the vscode-diana component of thautwarm, specifically the Jinja2 Template Handler's Gen.py file. An unknown function in this file contains a manipulation issue that enables injection attacks. This vulnerability requires local access, and the exploit has already been made public, increasing the risk for potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share