CVE-2025-27772 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/new_run` endpoint's `checks` and `metadata` parameters. Any user with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the cont [truncated]
CVE-2025-27771 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/add_prompts` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain. As [truncated]
CVE-2025-27770 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/create_project` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain.
CVE-2025-27621 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability arises from the creation of a default user with a static username and API key in version 0.7.1 and prior. Combined with an open CORS policy, this allows any website to make authenticated cross-origin requests to the UpTrain instance, potentially ena [truncated]