CVE-2025-27770: GHSL-2024-198_GHSL-2024-199: Zero click RCE in Uptrain - CVE-2025-27621, CVE-2025-27770
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27770?
CVE-2025-27770 has a risk score of 89, indicating a high severity level.
How do I fix CVE-2025-27770?
To mitigate CVE-2025-27770, implement strict authentication controls and review CORS policies to restrict access.
What types of systems are affected by CVE-2025-27770?
CVE-2025-27770 affects installations of the Uptrain dashboard that lack proper authentication and have an open CORS policy.
What is the primary threat posed by CVE-2025-27770?
The primary threat of CVE-2025-27770 is remote code execution, which allows an attacker to execute arbitrary code on the Uptrain host.
When was CVE-2025-27770 published?
CVE-2025-27770 was published on August 8, 2026.