CVE-2025-27608 - CVE House
Back to Database
Status published Low CVE-2025-27608

Self Cross-Site Scripting in Arduino IDE

Vulnerability Description

Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings section of the Arduino IDE interface. In the vulnerable versions, any values entered in this field are directly displayed to the user through a notification tooltip object, without a proper output encoding routine, due to the underlying ElectronJS engine interpretation. This vulnerability exposes the input parameter to Self-XSS attacks, which may lead to security risks depending on where the malicious payload is injected. This vulnerability is fixed in 2.3.5.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27608

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

arduino-ide
Vulnerable Versions:
< 2.3.5

Timeline

Official Publish: April 2nd, 2025
Last Modified: April 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)