CVE-2025-27621

Source
https://cve.org/CVERecord?id=CVE-2025-27621
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27621.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27621
Published
2026-08-17T15:42:30Z
Modified
2026-08-19T03:48:03Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
UpTrain has a Constant Default API Key
Details

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the username is also used as the default API key. The UpTrain backend also has an open CORS policy. Using these two primitives, any website can make a authenticated cross-origin request to the UpTrain instance by providing the default API key in the header uptrain-access-token. This issue may allow arbitrary websites to perform privileged operations on the UpTrain instance, as if they were the default logged in user. As of time of publication, no known patches are available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27621.json"
}
References

Affected packages

Git / github.com/uptrain-ai/uptrain

Affected ranges

Type
GIT
Repo
https://github.com/uptrain-ai/uptrain
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.7.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.0.8.1
v0.*
v0.0.1
v0.0.1-beta
v0.0.10
v0.0.11
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.5.1
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.6.0
v0.6.1
v0.6.10
v0.6.10.post1
v0.6.11
v0.6.12
v0.6.13
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.5.post1
v0.6.5.post2
v0.6.6
v0.6.6.post1
v0.6.6.post2
v0.6.6.post3
v0.6.7
v0.6.7.post1
v0.6.8
v0.6.9
v0.7.0
v0.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27621.json"