CVE-2025-0982: Sandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0982?
The severity of CVE-2025-0982 is classified as high due to its potential for allowing arbitrary unsandboxed code execution.
How do I fix CVE-2025-0982?
To fix CVE-2025-0982, upgrade to the latest version of Google Cloud Application Integration that no longer supports the Rhino engine.
What are the potential impacts of CVE-2025-0982?
The potential impacts of CVE-2025-0982 include unauthorized execution of code, data breaches, and possible disruption of services.
Is CVE-2025-0982 being addressed by Google?
Yes, Google has announced that support for Rhino will end on January 24, 2025, as a mitigation for CVE-2025-0982.
Who is affected by CVE-2025-0982?
Users of Google Cloud Application Integration that utilize the JavaScript Task feature are affected by CVE-2025-0982.