PT-2025-20578 · Jan · Jan

Published

2025-05-09

·

Updated

2025-12-27

·

CVE-2025-29509

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jan versions 0.5.14 and earlier
Description The software is susceptible to remote code execution (RCE) when a user clicks on a link displayed within a conversation. This occurs because the application opens external websites and exposes the electronAPI, specifically lacking URL filtering when calling the shell.openExternal() function.
Recommendations Versions prior to 0.5.14 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-29509

Affected Products

Jan