All 4 CVE vulnerabilities found in uptrain, with AI-generated Chinese analysis, references, and POCs.
Vendor: uptrain-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-27772 | Uptrain vulnerable to remote code execution via `/new_run` endpoint CWE-74 | 7.4 | High | 2026-08-17 |
| CVE-2025-27771 | Uptrain vulnerable to remote code execution via `/add_prompts` endpoint CWE-74 | 7.4 | High | 2026-08-17 |
| CVE-2025-27770 | UpTrain vulnerable to Remote code execution at `/create_project` CWE-74 | 7.4 | High | 2026-08-17 |
| CVE-2025-27621 | UpTrain has a Constant Default API Key CWE-287 | 7.7 | High | 2026-08-17 |
All 4 known CVE vulnerabilities affecting uptrain with full Chinese analysis, references, and POCs where available.