Impact
The vulnerability is an uncontrolled search path flaw (CWE‑427) that allows a user with local access to an AI Playground instance to cause the application to load binaries from unintended locations. Because the flaw can be triggered by an authenticated user and requires high attack complexity, it can lead to execution of arbitrary code with elevated privileges. This results in loss of confidentiality, integrity, and availability for the system as a whole.
Affected Systems
The flaw affects AI Playground software prior to version 3.0.0 alpha. No other vendors or product variants are listed as affected.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The impact can be realized through local access when the attacker has an authenticated session and can interact with the user. The required knowledge is minimal, so the likelihood of exploitation depends largely on user interaction.
OpenCVE Enrichment