Description
A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.
INFO
Published Date :
2025-10-17T15:36:12.710Z
Last Modified :
2025-10-17T15:48:52.236Z
Source :
HiddenLayer
AFFECTED PRODUCTS
The following products are affected by CVE-2025-62356 vulnerability.
| Vendors | Products |
|---|---|
| Qodo |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-62356.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact