CVE-2025-64689: Critical severity JetBrains YouTrack vulnerability
Published Nov 10, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to internal functionality that is not available to customers.
Affected Software
2 affected components
JetBrains YouTrack<2025.3.104432
JetBrains YouTrack<2025.3.104432
Event History
Nov 10, 2025
CVE Published
via MITRE·01:28 PM
Rejected
via MITRE·01:28 PM
Data Sourced
via NVD·02:15 PM
Description
Dec 2, 2025
Rejected
via MITRE·10:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-64689?
The severity of CVE-2025-64689 is considered high due to potential exposure of sensitive tokens.
2
How do I fix CVE-2025-64689?
To fix CVE-2025-64689, upgrade to JetBrains YouTrack version 2025.3.104432 or later.
3
What are the potential impacts of CVE-2025-64689?
CVE-2025-64689 could lead to unauthorized access to the global Junie token, compromising security.
4
Who is affected by CVE-2025-64689?
CVE-2025-64689 affects users of JetBrains YouTrack versions prior to 2025.3.104432.
5
Is there a workaround for CVE-2025-64689?
There are no known workarounds for CVE-2025-64689; the recommended action is to update the software.