CVE-2025-6193

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
Configurations

No configuration.

History

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Se descubrió una vulnerabilidad de inyección de comandos en el kit de herramientas TrustyAI Explainability. Los comandos arbitrarios colocados en ciertos campos de un recurso personalizado (CR) de LMEValJob pueden ejecutarse en la terminal del pod de LMEvalJob. Este problema puede ser explotado mediante un LMEvalJob malintencionado por un usuario con permisos para implementar un CR.

20 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-20 16:15

Updated : 2025-06-23 20:16


NVD link : CVE-2025-6193

Mitre link : CVE-2025-6193

CVE.ORG link : CVE-2025-6193


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')