CVE-2025-31951: HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
Published May 6, 2026
·Updated
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.
Affected Software
1 affected component
HCL BigFix RunBookAI
Event History
May 6, 2026
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31951?
The severity of CVE-2025-31951 is classified as critical due to its potential for unauthorized command execution.
2
How do I fix CVE-2025-31951?
To fix CVE-2025-31951, update HCL BigFix RunBookAI to the latest patched version as recommended by the vendor.
3
What are the potential impacts of CVE-2025-31951?
CVE-2025-31951 may allow attackers to execute unauthorized commands, leading to data breaches or system manipulation.
4
What software is affected by CVE-2025-31951?
CVE-2025-31951 specifically affects HCL BigFix RunBookAI.
5
Is there a known exploit for CVE-2025-31951?
As of now, there are no publicly known exploits for CVE-2025-31951, but the risk remains due to the nature of the vulnerability.