Impact
The vulnerability is an injection flaw that allows an authenticated user to execute arbitrary code on the host that runs the UpTrain service, typically the Docker container as used by the software. The exploit uses the public /new_run endpoint in UpTrain 0.7.1 and earlier, where unchecked checks and metadata parameters are evaluated. Successful exploitation would give the attacker full control over the container, potentially compromising the underlying host and any shared resources, severely affecting confidentiality, integrity, and availability.
Affected Systems
UpTrain version 0.7.1 and earlier, released by uptrain-ai under the repository uptrain. No other versions or vendors are listed as affected in the official CNA data.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity and the vulnerability is exploitable remotely. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the lack of a patched version and documented exploitation path increases concern. The vulnerability is not listed in the CISA KEV catalog. An attacker with a valid authentication token can trigger the exploit by sending a crafted payload to the /new_run endpoint. In the absence of a patch, the attack requires only authorized access to the UpTrain instance.
OpenCVE Enrichment