PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-27770 uptrain-ai CVE debrief

CVE-2025-27770 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/create_project` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain.

Vendor
uptrain-ai
Product
uptrain
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-18
Advisory published
2026-08-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for UpTrain instances, particularly those running version 0.7.1 or prior, should assess exposure and potential impact. This includes operators managing UpTrain deployments, platform administrators, vulnerability management teams, and security teams responsible for monitoring and incident response. These stakeholders should prioritize verifying exposure, evaluating the privileges of users with access to UpTrain, and implementing mitig

Why it matters

CVE-2025-27770 is a high-severity vulnerability in UpTrain, allowing for remote code execution via the `/create_project` endpoint. Defenders should prioritize verifying exposure and assessing potential impact.

  • Remote code execution may allow attackers to gain unauthorized access to the host running UpTrain.
  • Defenders should verify exposure and assess potential impact to prevent unauthorized access.
  • The vulnerability requires authentication, but the privileges required to exploit it are not specified.

Technical summary

The vulnerability affects version 0.7.1 and prior of UpTrain, allowing for remote code execution via the `/create_project` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain. This could lead to unauthorized access or control of the host system. The vulnerability requires authentication, but the specific privileges needed are not detailed in the available sources. Defenders should focus on verifying exposure and assessing potential impact.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for remote code execution.

Recommended defensive actions

  • Verify exposure by checking if the UpTrain instance is running version 0.7.1 or prior.
  • Assess potential impact by evaluating the privileges of users with access to UpTrain.
  • Implement compensating controls, such as restricting access to the `/create_project` endpoint.
  • Monitor for suspicious activity on the UpTrain instance.
  • Review vendor guidance for UpTrain and plan for updates or mitigations.
  • Conduct an inventory of assets using UpTrain to identify potentially affected systems.
  • Track exceptions and retest remediated assets to ensure vulnerability resolution.

Evidence notes

The vulnerability is described in the CVE record and NVD vulnerability detail page. The source references provide additional information on the vulnerability. Evidence is limited to publicly available details from these sources. Defenders should verify exposure and assess potential impact based on this information. No additional evidence is available at this time.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-27770 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-27770

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-27770 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-27770

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.