Impact
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 contain an input sanitization flaw that allows a remote attacker to execute arbitrary script code during web page generation. This flaw is an instance of CWE‑78 (OS Command Injection) and enables the attacker to run unintended commands on the host system, compromising confidentiality, integrity, and availability of the affected application.
Affected Systems
The vulnerability impacts IBM Engineering AI Hub from versions 1.0.0 through 1.2.0. Users running any of these released versions should verify that they are not operating the vulnerable build.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw can be triggered remotely via crafted input delivered to the web page generator. Unlike publicly disclosed exploits, it is not currently listed in the CISA KEV catalog, which implies that no mass‑mode exploitation has been confirmed yet.
OpenCVE Enrichment