📦

toolbox

Vendor: jetbrains

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 16 Total Indexed
Avg. EPSS 0.90% Exploit Prob.
Latest CVE CVE-2025-43014 Apr 17

Security Vulnerability Index

Page 1 / 2
6.1 CVSS

In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation

EPSS: 0.22%
6.9 CVSS

In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible

EPSS: 0.15%
8.3 CVSS

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

EPSS: 0.61%
4.2 CVSS

In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

EPSS: 0.19%
5.3 CVSS

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

EPSS: 0.41%
5.2 CVSS

In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible

EPSS: 0.21%
9.8 CVSS

JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.

EPSS: 4.38%
7.5 CVSS

JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

EPSS: 1.37%
7.5 CVSS

In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

EPSS: 0.69%
7.3 CVSS

In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

EPSS: 1.04%