What is CVE-2025-27772?
CVE-2025-27772 is a remote code execution (RCE) vulnerability in the `/new_run` endpoint of the open-source UpTrain platform, affecting versions 0.7.1 and prior, via the `checks` and `metadata` parameters. Any authenticated user can exploit this to execute arbitrary code on the system. Affected administrators should urgently upgrade to the latest version and review network access controls.
Azərbaycanca: CVE-2025-27772, UpTrain açıq mənbə platformasının 0.7.1 və əvvəlki versiyalarında `/new_run` endpointində `checks` və `metadata` parametrləri vasitəsilə uzaqdan kod icrası (RCE) zəifliyidir. Bu zəiflik autentifikasiya olunmuş istənilən istifadəçiyə sistemdə ixtiyari kod icra etməyə imkan verir. Təsirə məruz qalan sistemlərin administratorları dərhal UpTrain-i ən son versiyaya yeniləməli və şəbəkə giriş nəzarətlərini nəzərdən keçirməlidir.
FAQ2
Which versions of UpTrain are affected by CVE-2025-27772?
The vulnerability affects UpTrain versions 0.7.1 and prior.
Is authentication required to exploit CVE-2025-27772?
Yes, any authenticated user can exploit this RCE vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.