CVE-2025-27621: GHSL-2024-198_GHSL-2024-199: Zero click RCE in Uptrain - CVE-2025-27621, CVE-2025-27770
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27621?
CVE-2025-27621 has a risk score of 91, indicating a high severity level.
How do I fix CVE-2025-27621?
To fix CVE-2025-27621, ensure proper authentication mechanisms are implemented and restrict the open CORS policy in the Uptrain dashboard.
What are the potential impacts of CVE-2025-27621?
CVE-2025-27621 could allow unauthorized remote code execution on the Uptrain host without user interaction.
Who is affected by CVE-2025-27621?
Users of the Uptrain dashboard are affected by CVE-2025-27621 due to its lack of significant authentication.
What conditions allow exploitation of CVE-2025-27621?
CVE-2025-27621 can be exploited when an Uptrain user is directed to a specially crafted payload due to the open CORS policy.