---
id: CVE-2025-52641
title: >-
  HCL AION is affected by a vulnerability where certain system behaviours may
  allow exploration of internal filesystem structures
summary: >-
  HCL AION is affected by a vulnerability where certain system behaviours may
  allow exploration of internal filesystem structures. Exposure of such
  information may provide insights into the underlying environment, which could
  potentially a…
severity: low
cvss: 2.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-209
vendor: hcltech
product: aion
affected:
  - 'aion >= 2.0.0, < 2.1.2'
patched:
  - aion 2.1.2
published: '2026-04-15'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-52641'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130007
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00116
epssPercentile: 0.0145
ingestedAt: '2026-09-30T22:27:27.755Z'
---

## Overview

HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which could potentially aid in further targeted actions or limited information disclosure.

## Affected

- `aion >= 2.0.0, < 2.1.2`

## Remediation

Upgrade past the affected range:

- `aion 2.1.2`
