Junglewise Threat Intelligence

CVE-2025-59340: HubSpot Jinjava sandbox bypass via JavaType deserialization

CVE-2025-59340 · Severity: critical · CVSS 9.8 · Published 2025-09-17

Executive brief

HubSpot Jinjava is a Java-based template engine used to generate dynamic content. A security flaw allows an attacker to bypass the engine's safety sandbox by manipulating internal Java objects. This could allow an unauthorized user to read sensitive local files, access internal network resources, or potentially take full control of the server.

Technical details

A sandbox bypass exists in Jinjava due to improper neutralization of special elements in the template engine (CWE-1336). Attackers can access the internal '____int3rpr3t3r____' variable to reach the ObjectMapper configuration. By leveraging the 'JavaType' class and 'constructFromCanonical' method, which were not restricted by the JinjavaBeanELResolver, an attacker can deserialize input into arbitrary Java classes. This primitive allows for the instantiation of dangerous classes like java.net.URL, leading to arbitrary file read, SSRF, and potentially remote code execution. The vulnerability is patched in versions 2.8.1 and 2.7.5.

Affected products

  • HubSpot jinjava = 2.8.0, >= 2.7.0, < 2.7.5

Timeline

  • 2025-09-17: disclosed
  • 2025-09-17: advisory
  • 2025-09-17: patched

References