FixVibe

critical

HubSpot Jinjava JavaType Sandbox Bypass (CVE-2025-59340)

CVE-2025-59340 affects HubSpot Jinjava versions >=2.7.0 and <2.7.5, and version 2.8.0. A JavaType deserialization sandbox bypass may enable arbitrary file reads or SSRF and, in some deployments, follow-on RCE; RCE is not guaranteed. FixVibe repository scans flag affected Jinjava versions.

CVE-2025-59340GHSA-m49c-g9wr-hv6vCWE-1336

Affected versions and impact

HubSpot Jinjava is affected in versions >= 2.7.0 and < 2.7.5, and in version 2.8.0. The JavaType deserialization sandbox bypass can enable sandbox escape primitives such as arbitrary file reads or SSRF and, in some deployments, follow-on remote code execution. RCE is not guaranteed: impact depends on how the application uses Jinjava and whether untrusted templates can reach the affected behavior [S1][S2][S3].

How FixVibe covers it

FixVibe's repository scans flag Maven and Gradle projects that resolve an affected com.hubspot.jinjava:jinjava version, reported as a version-based advisory with the version and file.

Remediation

Upgrade to Jinjava 2.7.5 or 2.8.1, or the current supported release, then rebuild and verify the dependency tree and deployed runtime. Restrict untrusted template input and review where template rendering is reachable. Follow the HubSpot advisory and the linked ecosystem records for release-specific guidance [S1][S2][S3][S4].