AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-0982

CRITICAL · CVSS 10 EPSS 0.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. It affects Java.

CVE
CVE-2025-0982
Severity
CRITICAL
CVSS
10
EPSS
0.25%
Java

Original NVD Description

Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed.

Related CVEs

Other vulnerabilities affecting the same vendor(s)