CVE-2025-43012

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 77

Summary

CVE-2025-43012 is a vulnerability affecting JetBrains Toolbox App prior to version 2.6. This issue permits command injection through the SSH plugin, allowing an attacker to execute arbitrary commands on an affected system with the privileges of the Toolbox App user. This could potentially lead to data theft, unauthorized system modifications, or other malicious activities. Users are urged to update their JetBrains Toolbox App to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share