Usebruno develops Bruno, an API client and testing tool positioned as a lightweight alternative to established development platforms, with a vulnerability footprint centered on supply-chain and client-side attack vectors. The recurring weakness classes—including unsafe code downloads, embedded malicious code, cross-site scripting, permissive cross-domain policies, and open redirects—reflect the inherent risks of a tool that integrates with external services, processes untrusted requests, and executes client-side logic. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usebruno over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34841CRITICAL Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, whi | Apr 6, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-30210MEDIUM Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this cas | Apr 1, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-48463MEDIUM Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs viewer. | Nov 4, 2024 | 6.5 | 19 | NO | NO |
CVE-2025-30354MEDIUM Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The b | Apr 1, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usebruno.
Media articles that mention a CVE ID that affects a product developed by Usebruno — matched by CVE ID, not by vendor name.