Junglewise Threat Intelligence

CVE-2025-0982: Google Application Integration JavaScript RCE via Rhino engine

CVE-2025-0982 · Severity: high · Published 2026-06-25

Technologies: Google Cloud Platform. Vendors: Google.

Executive brief

Google Cloud's Application Integration service contained a vulnerability in its JavaScript task execution engine (Rhino) that could allow arbitrary code execution. The flaw affected tasks deployed before January 2025. This could enable attackers to execute malicious code within customer integration workflows, potentially compromising connected applications and data processing pipelines.

Technical details

A vulnerability exists in the Rhino JavaScript engine integration within Google Cloud's Application Integration service. The flaw affects JavaScript tasks that were published prior to January 2025. The exact attack vector and preconditions are not detailed in the advisory, but the scope is limited to legacy tasks created before the cutoff date. An attacker could potentially exploit this to execute arbitrary JavaScript code within the context of the integration service. Remediation is available through task republishing or service updates after January 2025.

Affected products

  • Google Application Integration Tasks published before January 2025

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats