Description

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.

INFO

Published Date :

2025-10-17T15:36:12.710Z

Last Modified :

2025-10-17T15:48:52.236Z

Source :

HiddenLayer
AFFECTED PRODUCTS

The following products are affected by CVE-2025-62356 vulnerability.

Vendors Products
Qodo
  • Gen Ide
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-62356.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact