PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-11919 Wolfram Research Inc. CVE debrief

The CVE-2025-11919 vulnerability affects Wolfram Research Inc.'s Cloud product, allowing attackers to execute arbitrary code by manipulating the classpath. This critical vulnerability enables attackers to load malicious classes during JVM startup by strategically placing them in the /tmp/ space, which is shared among users on the same cloud instance. The vulnerability exists due to the default JVM's ability to access files and directories under /tmp/, including the $TemporaryDirectory of other users. Defenders should prioritize verifying and mitigating this vulnerability, especially in cloud instances where multiple users share the /tmp/ space. Evidence is limited to CVE and NVD .

Vendor
Wolfram Research Inc.
Product
Cloud
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-26
Original CVE updated
2026-09-29
Advisory published
2026-06-26
Advisory updated
2026-09-29

Who should care

Defenders responsible for cloud instances, especially those using Wolfram Research Inc.'s Cloud product, should assess exposure and prioritize mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and mitigate the vulnerability in their environments.

Why it matters

This critical vulnerability allows attackers to execute arbitrary code by manipulating the classpath in Wolfram Research Inc.'s Cloud product. Defenders should prioritize verification and mitigation, especially in cloud instances where multiple users share the /tmp/ space. The vulnerability requires verification of affected versions and remediation priority. Evidence is limited to CVE and NVD records.

  • Potential code execution through malicious class loading
  • Elevation of privileges in cloud instances
  • Lateral movement within cloud environments

Technical summary

The default JVM can access files and directories under /tmp/ including the $TemporaryDirectory of other users on the same cloud instance (/tmp/UserTemporaryFiles/). An attacker with access to the shared /tmp/ space can preemptively create or replace .jar files or directories (via the -init file) that the victim JVM will resolve first in its classpath. By strategically placing a malicious version of a commonly used library, an attacker can cause the JVM to load the malicious class during startup, thereby executing the attacker's code.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially in cloud instances where multiple users share the /tmp/ space.

Recommended defensive actions

  • Verify and apply vendor patches or updates to prevent exploitation
  • Restrict access to the /tmp/ space in cloud instances
  • Monitor for suspicious activity in the /tmp/ directory
  • Consider implementing additional security controls for cloud instances
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability. Additional information from the vendor and other sources is limited. The vulnerability requires verification of affected versions and remediation priority. Evidence limits are noted, and defenders should verify the vulnerability's impact on their systems. Limited source detail is available, so explicit evidence-limit language and defensive verification tasks are necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-11919 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-11919

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-11919 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11919

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/PeterRoberge/vulnerability-wolfram-cloud-14.2/blob/main/disclosure.md

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.kb.cert.org/vuls/id/553375

    af854a3a-2127-422b-91ae-364da2661108

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.