PatchSiren cyber security CVE debrief
CVE-2025-11919 Wolfram Research Inc. CVE debrief
The CVE-2025-11919 vulnerability affects Wolfram Research Inc.'s Cloud product, allowing attackers to execute arbitrary code by manipulating the classpath. This critical vulnerability enables attackers to load malicious classes during JVM startup by strategically placing them in the /tmp/ space, which is shared among users on the same cloud instance. The vulnerability exists due to the default JVM's ability to access files and directories under /tmp/, including the $TemporaryDirectory of other users. Defenders should prioritize verifying and mitigating this vulnerability, especially in cloud instances where multiple users share the /tmp/ space. Evidence is limited to CVE and NVD .
- Vendor
- Wolfram Research Inc.
- Product
- Cloud
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-26
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-06-26
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for cloud instances, especially those using Wolfram Research Inc.'s Cloud product, should assess exposure and prioritize mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify and mitigate the vulnerability in their environments.
Why it matters
This critical vulnerability allows attackers to execute arbitrary code by manipulating the classpath in Wolfram Research Inc.'s Cloud product. Defenders should prioritize verification and mitigation, especially in cloud instances where multiple users share the /tmp/ space. The vulnerability requires verification of affected versions and remediation priority. Evidence is limited to CVE and NVD records.
- Potential code execution through malicious class loading
- Elevation of privileges in cloud instances
- Lateral movement within cloud environments
Technical summary
The default JVM can access files and directories under /tmp/ including the $TemporaryDirectory of other users on the same cloud instance (/tmp/UserTemporaryFiles/). An attacker with access to the shared /tmp/ space can preemptively create or replace .jar files or directories (via the -init file) that the victim JVM will resolve first in its classpath. By strategically placing a malicious version of a commonly used library, an attacker can cause the JVM to load the malicious class during startup, thereby executing the attacker's code.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in cloud instances where multiple users share the /tmp/ space.
Recommended defensive actions
- Verify and apply vendor patches or updates to prevent exploitation
- Restrict access to the /tmp/ space in cloud instances
- Monitor for suspicious activity in the /tmp/ directory
- Consider implementing additional security controls for cloud instances
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability. Additional information from the vendor and other sources is limited. The vulnerability requires verification of affected versions and remediation priority. Evidence limits are noted, and defenders should verify the vulnerability's impact on their systems. Limited source detail is available, so explicit evidence-limit language and defensive verification tasks are necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11919 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11919
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11919 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11919
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/PeterRoberge/vulnerability-wolfram-cloud-14.2/blob/main/disclosure.md
-
Source reference
Unverified legacy reference
URL: https://www.kb.cert.org/vuls/id/553375
af854a3a-2127-422b-91ae-364da2661108
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.