---
id: CVE-2025-31995
title: HCL Unica MaxAI Workbench is vulnerable to improper input validation
summary: >-
  HCL Unica MaxAI Workbench is vulnerable to improper input validation.  This
  allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or
  command injection, leading to unauthorized access or data breaches, etc.
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-20
published: '2025-10-13'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31995'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124425
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00501
epssPercentile: 0.40582
ingestedAt: '2026-09-30T23:29:32.427Z'
---

## Overview

HCL Unica MaxAI Workbench is vulnerable to improper input validation.  This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading to unauthorized access or data breaches, etc.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
