A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Oct 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2025-10-17T15:48:52.236Z
Reserved: 2025-10-10T13:18:25.508Z
Link: CVE-2025-62356

Updated: 2025-10-17T15:48:17.026Z

Status : Received
Published: 2025-10-17T16:15:39.283
Modified: 2025-10-17T16:15:39.283
Link: CVE-2025-62356

No data.

No data.