CVE-2025-27771None▾ SunlitUpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user th…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.8%
UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the /add_prompts endpoint is vulnerable to remote code execution via the checks and metadata parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-27772NoneUpTrain is an open-source platform to evaluate and improve generative AI applications
CVE-2022-27924High· 7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance
CVE-2022-23064High· 8.8snipe-IT vulnerable to host header injection
CVE-2026-61732Critical· 10.0Decepticon is an autonomous hacking agent for red teams
CVE-2026-47644Medium· 6.5Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-42835High· 8.1Microsoft Teams for Android Information Disclosure Vulnerability