Deserialization Vulnerability in Jinjava by HubSpot
CVE-2025-59340
9.8CRITICAL
What is CVE-2025-59340?
A deserialization vulnerability in Jinjava, a Java-based template engine from HubSpot, allows attackers to manipulate object deserialization processes. By exploiting an improper configuration in versions prior to 2.8.1, an attacker could instruct the ObjectMapper to deserialize controlled input into arbitrary classes. This flaw can lead to the instantiation of sensitive classes, including java.net.URL, permitting unauthorized access to local files and remote resources. This risk opens a pathway for potential remote code execution, enabling further exploits. The vulnerability has been addressed in version 2.8.1.
Affected Version(s)
jinjava < 2.8.1