GHSL-2024-198: _GHSL-2024-199: Zero click RCE in Uptrain - CVE-2025-27621, CVE-2025-27770
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2024-198?
The severity of GHSL-2024-198 is rated as high with a risk score of 89.
How do I fix GHSL-2024-198?
To fix GHSL-2024-198, implement proper authentication mechanisms and review CORS policies in the Uptrain dashboard.
What vulnerabilities are included in GHSL-2024-198?
GHSL-2024-198 includes vulnerabilities CVE-2025-27621 and CVE-2025-27770, which lead to zero click remote code execution.
Who is affected by GHSL-2024-198?
Users of the Uptrain dashboard are affected by GHSL-2024-198 due to its security flaws.
What type of attack does GHSL-2024-198 enable?
GHSL-2024-198 enables zero click remote code execution attacks, allowing attackers to execute arbitrary code on the Uptrain host.