Impact
Guardrails‑detectors’ file_type content detector processes user‑supplied XML Schema Definition strings without restrictions. Because the schema is parsed and applied against data, a malicious attacker can embed external references or file paths. When processed, the system may perform server‑side HTTP requests to arbitrary URLs or read local files, exposing secrets such as cloud credentials or internal network information. This flaw is catalogued as CWE‑918 and can lead to undisclosed data being exposed through remote file reads or outbound requests, rendering it a high‑severity information‑disclosure vulnerability.
Affected Systems
Red Hat OpenShift AI (RHOAI) is affected. No specific product versions are listed, so any deployment of RHOAI that includes guardrails‑detectors may be vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical. The EPSS score is less than 1%, indicating a low but non‑zero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for remote SSRF and local file read remains significant. Attackers can target any exposed interface that accepts XML schema definitions, making the risk notable for systems that receive untrusted input.
OpenCVE Enrichment