CVE-2025-10492: Cloud JasperReports Io

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library

Affected products

  • Cloud JasperReports Io: up to and including 4.0.0
  • Cloud JasperReports Library: up to and including 7.0.3; up to and including 9.0.2
  • Cloud JasperReports Server: up to and including 9.0.0
  • Cloud JasperReports Studio: up to and including 7.0.3; up to and including 9.0.2
  • Cloud JasperReports Web Studio: up to and including 3.0.1

Published 2025-09-16. Last modified 2026-06-17.