HIGH🇵🇱 Wersja polska

CVE-2025-30354

CVSS 8.7v4.0pub. 2025-04-01upd. 2025-09-22

Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The bug resulted in the sandbox settings to be ignored for the particular case where a single request is run/sent. This vulnerability's attack surface is limited strictly to scenarios where users import collections from untrusted or malicious sources. The exploit requires deliberate action from the user—specifically, downloading and opening an externally provided malicious Bruno collection. The vulnerability is fixed in 1.39.1.

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Usebruno Bruno

    APP
    Usebruno
    < 1.39.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-34841CRITICAL9.8PL ✓same product

Atak na łańcuch dostaw Bruno via skompromitowany pakiet axios – instalacja RAT

CVE-2025-30210HIGH8.7same product

Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components wh...

CVE-2024-48463MEDIUM6.5same product

Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows...