CVE-2025-58335
Jetbrains Junie ≤ 243.284.50
Raw vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:NSummary
CVE-2025-58335 is a medium-severity Product UI does not Warn User of Unsafe Actions (CWE-356) vulnerability in Jetbrains Junie. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique User Execution (T1204); ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-26121
Vulnerability Data
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 1 hardening rule · 1 OS baseline
—
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Mandates explicit user-visible indication, directly countering absence of warnings for device activation.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices include UI design requirements that warn users before unsafe actions.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can verify presence of warnings for unsafe user actions.
Security awareness training can teach users to heed or demand warnings for unsafe actions.
Secure development life cycle requires UI design to warn users before unsafe actions.
Application security requirements include user warnings for dangerous operations.
Secure architecture principles can mandate confirmation prompts for risky actions.
Secure coding practices can embed user warnings before unsafe operations.