CVE-2025-6193Medium· 5.9▾ SunlitA command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be e…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37902High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37899High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37900High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37901High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37898High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface