Impact
The vulnerability is an unsafe URL redirection flaw (CWE‑601) that allows a remote attacker to supply an unvalidated URL to IBM Engineering AI Hub, causing users to be redirected to malicious websites.
Affected Systems
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are affected. The flaw is resolved in the 1.0.01.3.0, 1.1.01.3.0, and 1.2.01.3.0 releases, with upgrade guidance provided by IBM.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score below 1% suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw by presenting a crafted URL to a user, leading to an automatic redirection once the user interacts with the link.
OpenCVE Enrichment