CVE-2025-43014
Published Apr 17, 2025In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Vendor/product archive
11 CVEs tagged to jetbrains / toolbox — 1 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.