CVE-2025-30210 - CVE House
Back to Database
Status published High CVE-2025-30210

Bruno XSS On Environment Name

Vulnerability Description

Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this case the Environment name) as raw HTML which then gets injected into DOM on hover. This, combined with loose Content Security Policy restrictions, allowed any valid HTML text containing inline script to get executed on hovering over the respective Environment's name. This vulnerability's attack surface is limited strictly to scenarios where users import collections from untrusted or malicious sources. The exploit requires deliberate action from the user—specifically, downloading and opening an externally provided malicious Bruno or Postman collection export and the user hovers on the environment name. This vulnerability is fixed in 1.39.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30210

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

bruno
Vulnerable Versions:
>= 1.38.0, < 1.39.1

Timeline

Official Publish: April 1st, 2025
Last Modified: April 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)