GHSL-2024-199: GHSL-2024-198_GHSL-2024-199: Zero click RCE in Uptrain - CVE-2025-27621, CVE-2025-27770
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2024-199?
GHSL-2024-199 has a severity rating of 89, indicating a critical vulnerability.
How do I fix GHSL-2024-199?
To fix GHSL-2024-199, implement authentication controls and restrict the CORS policy for the Uptrain dashboard.
What are the main risks associated with GHSL-2024-199?
The main risks of GHSL-2024-199 include potential unauthorized remote code execution and data exposure through improper access controls.
Which versions of Uptrain are affected by GHSL-2024-199?
GHSL-2024-199 affects specific versions of the Uptrain dashboard that lack adequate authentication and security measures.
What type of attack does GHSL-2024-199 facilitate?
GHSL-2024-199 facilitates zero click remote code execution attacks.