Arduino's vulnerability footprint centers on a modestly represented set of development tools and microcontroller platforms, including its integrated development environment, firmware, and educational applications, which reach users across embedded systems and maker communities. The recurring weakness classes—path traversal, default permission errors, cross-site scripting in web interfaces, and OS command injection—reflect the mixed trust boundaries between local development tooling, web-based components, and embedded firmware that characterize this vendor's product stack. Current exploitation activity, severity distribution, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arduino over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64724HIGH Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application compo | Dec 18, 2025 | 7.3 | 24 | NO | NO |
CVE-2023-43800HIGH Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP | Oct 18, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-43802HIGH Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user | Oct 18, 2023 | 7.8 | 24 | NO | NO |
CVE-2019-13991MEDIUM Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity. | Jul 19, 2019 | 6.5 | 23 | NO | NO |
CVE-2023-43801HIGH Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplie | Oct 18, 2023 | 7.1 | 22 | NO | NO |
CVE-2023-43803HIGH Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplie | Oct 18, 2023 | 7.1 | 22 | NO | NO |
CVE-2026-25933MEDIUM Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. Th | Feb 12, 2026 | 6.8 | 21 | NO | NO |
CVE-2025-64723MEDIUM Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass ma | Dec 18, 2025 | 4.4 | 18 | NO | NO |
CVE-2023-49296MEDIUM The Arduino Create Agent allows users to use the Arduino Create applications to upload code to any USB connected Arduino board directly from the browser. A vulnerability in version | Dec 13, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arduino.
Media articles that mention a CVE ID that affects a product developed by Arduino — matched by CVE ID, not by vendor name.