CVE-2025-62356

7.5

Qodo · Qodo Gen IDE

A path traversal vulnerability in Qodo Gen IDE allows unauthenticated attackers to read arbitrary local files on the user system via direct access or indirect prompt injection.

Executive summary

All versions of the Qodo Gen IDE are vulnerable to a path traversal flaw that permits unauthenticated attackers to read arbitrary files on the host system.

Vulnerability

This is a path traversal vulnerability (CWE-22) that allows an attacker to bypass directory restrictions to access local files. The vulnerability can be exploited by an unauthenticated attacker through direct interaction or by leveraging indirect prompt injection.

Business impact

The ability to read arbitrary files on a developer's workstation poses a significant risk to intellectual property, as attackers can extract sensitive source code, configuration files, and credentials. Given the CVSS score of 7.5, this high-severity flaw could lead to extensive data compromise and potential lateral movement within the development environment.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest security updates or patches, as no specific fixed version is currently documented.

Proactive Monitoring: Monitor workstation file access logs for unusual read patterns or access to files outside of the expected project directory structure.

Compensating Controls: Restrict IDE network access where possible and avoid processing untrusted or external prompts within the IDE until a vendor-supplied patch is applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a critical risk to development environments due to the potential for unauthorized access to sensitive source code. Organizations should prioritize identifying all instances of the Qodo Gen IDE within their infrastructure and apply vendor-provided updates as soon as they become available to mitigate the risk of file exfiltration.

Sources