CVE-2025-27770

Source
https://cve.org/CVERecord?id=CVE-2025-27770
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27770.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-27770
Published
2026-08-17T15:43:21Z
Modified
2026-08-20T03:30:13Z
Severity
  • 7.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
UpTrain vulnerable to Remote code execution at `/create_project`
Details

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the /create_project endpoint is vulnerable to remote code execution via the checks and metadata parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-74"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27770.json"
}
References

Affected packages

Git / github.com/uptrain-ai/uptrain

Affected ranges

Type
GIT
Repo
https://github.com/uptrain-ai/uptrain
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.7.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.0.8.1
v0.*
v0.0.1
v0.0.1-beta
v0.0.10
v0.0.11
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.5.1
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.6.0
v0.6.1
v0.6.10
v0.6.10.post1
v0.6.11
v0.6.12
v0.6.13
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.5.post1
v0.6.5.post2
v0.6.6
v0.6.6.post1
v0.6.6.post2
v0.6.6.post3
v0.6.7
v0.6.7.post1
v0.6.8
v0.6.9
v0.7.0
v0.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27770.json"