CVE-2025-70045

High
|7.4
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to intercept and manipulate secure communications because the application does not properly validate TLS/SSL certificates, making it susceptible to man-in-the-middle attacks. This issue occurs when the application is configured to treat secure connections as valid without checking if the certificates are trustworthy.

Technical Description

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSecure' is true

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$1,842($1K-$5K)
Vendor Response
Grade APatched in 3 days

Quick Information

Published

Feb 23, 2026

about 1 month ago

Last Modified

Feb 26, 2026

about 1 month ago

Vendor

jxcore

Product

jxm