PatchSiren

uptrain-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH uptrain-ai CVE published 2026-08-17

CVE-2025-27772

CVE-2025-27772 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/new_run` endpoint's `checks` and `metadata` parameters. Any user with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the cont [truncated]

HIGH uptrain-ai CVE published 2026-08-17

CVE-2025-27771

CVE-2025-27771 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/add_prompts` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain. As [truncated]

HIGH uptrain-ai CVE published 2026-08-17

CVE-2025-27770

CVE-2025-27770 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability affects version 0.7.1 and prior, allowing for remote code execution via the `/create_project` endpoint. Users with access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain.

HIGH uptrain-ai CVE published 2026-08-17

CVE-2025-27621

CVE-2025-27621 is a high-severity vulnerability in UpTrain, an open-source platform for evaluating and improving generative AI applications. The vulnerability arises from the creation of a default user with a static username and API key in version 0.7.1 and prior. Combined with an open CORS policy, this allows any website to make authenticated cross-origin requests to the UpTrain instance, potentially ena [truncated]