Injection Vulnerability in thautwarm vscode-diana Product by Vendor thautwarm
CVE-2025-3804
Key Information:
- Vendor
Thautwarm
- Status
- Vendor
- CVE Published:
- 19 April 2025
Badges
What is CVE-2025-3804?
A vulnerability has been identified in thautwarm's vscode-diana version 0.0.1, specifically within the Gen.py file associated with the Jinja2 Template Handler. This issue pertains to improper handling of user inputs that could lead to injection attacks. Local exploitation is necessary, allowing malicious users to take advantage of this flaw. The details of this vulnerability have been publicly disclosed, heightening the urgency for affected users to apply the necessary updates or safeguards to their systems.
Affected Version(s)
vscode-diana 0.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved