216.73.216.233

CVE-2025-30354

· Published 01/04/2025 15:16 · Modified 01/04/2025 20:26

Labels: CVE-2025-30354 2025-04-01CVE-2025-30354CWE-942[email protected]

Essential information

Published
01/04/2025 15:16
Modified
01/04/2025 20:26
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The bug resulted in the sandbox settings to be ignored for the particular case where a single request is run/sent. This vulnerability's attack surface is limited strictly to scenarios where users import collections from untrusted or malicious sources. The exploit requires deliberate action from the user—specifically, downloading and opening an externally provided malicious Bruno collection. The vulnerability is fixed in 1.39.1.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bruno / bruno cpe:2.3:a:bruno:bruno:1.39.1:*:*:*:*:*:*:*

References