CVE-2025-27772: GHSL-2024-200_GHSL-2024-201: Zero click RCE in Uptrain - CVE-2025-27771, CVE-2025-27772
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27772?
CVE-2025-27772 has a risk rating of 89, indicating a high severity level.
How do I fix CVE-2025-27772?
To mitigate CVE-2025-27772, ensure proper authentication mechanisms are implemented and restrict the CORS policy in the Uptrain dashboard.
What type of vulnerability is CVE-2025-27772?
CVE-2025-27772 is a remote code execution vulnerability that allows attackers to execute arbitrary code on the Uptrain host.
How can attackers exploit CVE-2025-27772?
Attackers can exploit CVE-2025-27772 by directing an Uptrain user to a specially crafted URL, leveraging the lack of authentication.
What software is affected by CVE-2025-27772?
The CVE-2025-27772 vulnerability affects the Uptrain dashboard.