What is CVE-2025-27771?
In UpTrain version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any authenticated user with access to the platform can exploit this to run arbitrary code on the server. Immediate upgrade to the latest version is strongly recommended.
Azərbaycanca: UpTrain platformasının 0.7.1 və əvvəlki versiyalarında `/add_prompts` endpoint-i `checks` və `metadata` parametrləri vasitəsilə remote code execution (RCE) zəifliyinə məruz qalır. Doğrulanmış istənilən istifadəçi bu boşluqdan istifadə edərək serverdə ixtiyari kod icra edə bilər. Dərhal platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of the UpTrain platform are affected by CVE-2025-27771?
The vulnerability affects UpTrain platform version 0.7.1 and prior versions.
What permissions does an attacker need to exploit CVE-2025-27771?
Any authenticated user with access to the platform can exploit this RCE vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.