CVE Explorer
CVE-2025-62356
A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Qodo Gen","vendor":"Qodo","versions":[{"status":"affected","version":"*"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3489d1c276257d4ac565609d7940c8b04a2b1371736b6c7300f0202728d4b950 · sha256:1b462147af1ae2c7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3489d1c276257d4ac565609d7940c8b04a2b1371736b6c7300f0202728d4b950 · sha256:1b462147af1ae2c7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3489d1c276257d4ac565609d7940c8b04a2b1371736b6c7300f0202728d4b950 · sha256:1b462147af1ae2c7… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://hiddenlayer.com/sai_security_advisor/2025-10-qodogen/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3489d1c276257d4ac565609d7940c8b04a2b1371736b6c7300f0202728d4b950 · sha256:1b462147af1ae2c7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.