Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NSummary
CVE-2025-57730 is a medium-severity Basic XSS (CWE-80) vulnerability in Jetbrains Intellij Idea. Its CVSS base score is 5.2 (Medium).
Operationally, ranked at the 35th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and AC-17 (Remote Access) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-28620
Vulnerability Data
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation and sanitization of untrusted input to block HTML/script injection, addressing the root cause of CWE-80 in the Remote Development feature.
Requires authorization, encryption, and usage restrictions for remote access sessions, limiting exposure of the vulnerable Remote Development feature.
Enforces least functionality by disabling or restricting the Remote Development feature unless explicitly required, reducing the attack surface for HTML injection.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require output encoding and input validation that prevent basic XSS.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development catches unneutralized script tags before release.
Secure SDLC mandates input validation and output encoding that directly prevent basic XSS.
Application security requirements explicitly call for neutralization of script-related HTML tags.
Secure coding standards require proper escaping of <, >, & to block XSS.
Web filtering can block some reflected XSS payloads at the network edge.