CVE-2025-43012: Command Injection
Published Apr 17, 2025
·Updated
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
Affected Software
2 affected components
JetBrains Toolbox App<2.6
JetBrains Toolbox<2.6
Event History
Apr 17, 2025
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 14, 57721
Event
via NVD·06:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-43012?
CVE-2025-43012 has a high severity due to its potential for command injection in the SSH plugin.
2
How do I fix CVE-2025-43012?
To fix CVE-2025-43012, update to JetBrains Toolbox App version 2.6 or later.
3
What impact does CVE-2025-43012 have on users?
CVE-2025-43012 allows an attacker to execute arbitrary commands on the system via the SSH plugin.
4
Which versions of JetBrains Toolbox App are affected by CVE-2025-43012?
Versions of JetBrains Toolbox App prior to 2.6 are affected by CVE-2025-43012.
5
Is there a workaround for CVE-2025-43012 if I cannot update?
There is no official workaround for CVE-2025-43012, so it is strongly recommended to update to the latest version.