A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Jun 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR. | |
Title | Trustyai-explainability: command injection via lmevaljob cr | |
First Time appeared |
Redhat
Redhat openshift Ai |
|
Weaknesses | CWE-78 | |
CPEs | cpe:/a:redhat:openshift_ai | |
Vendors & Products |
Redhat
Redhat openshift Ai |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-06-20T15:54:13.855Z
Updated: 2025-06-20T17:23:27.447Z
Reserved: 2025-06-16T22:22:28.761Z
Link: CVE-2025-6193

Updated: 2025-06-20T17:21:20.491Z

Status : Received
Published: 2025-06-20T16:15:29.713
Modified: 2025-06-20T16:15:29.713
Link: CVE-2025-6193
