VendorsJetBrainstoolboxall versions
Vulnerabilities

JetBrains Toolbox

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2020-25207
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
Published 2020-11-16 · Modified
10.0EPSS 0.046
CVE-2025-43012
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
Published 2025-04-17 · Analyzed
9.8EPSS 0.006
CVE-2022-48481
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
Published 2023-04-28 · Modified
7.8EPSS 0.002
CVE-2020-25013
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
Published 2020-11-16 · Modified
7.5EPSS 0.014
CVE-2019-18368
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
Published 2019-10-31 · Modified
7.5EPSS 0.010
CVE-2020-15827
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
Published 2020-08-08 · Modified
7.5EPSS 0.007
CVE-2025-43013
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Published 2025-04-17 · Analyzed
7.5EPSS 0.002
CVE-2025-43014
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Published 2025-04-17 · Analyzed
6.5EPSS 0.002
CVE-2025-42921
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
Published 2025-04-17 · Analyzed
6.5EPSS 0.002
CVE-2019-14959
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
Published 2019-10-02 · Modified
5.9EPSS 0.007
CVE-2024-24943
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
Published 2024-02-06 · Modified
5.5EPSS 0.004