CVE-2025-27621: UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U
Summary
UpTrain (a platform for testing and improving AI systems) in version 0.7.1 and earlier has a security flaw where it creates a default user with a predictable API key (a credential for accessing the system) and allows requests from any website due to an open CORS policy (cross-origin resource sharing, which controls whether websites can make requests to other domains). This means attackers could use any website to make authenticated requests to UpTrain and perform unauthorized actions as the default user.
Vulnerability Details
EPSS: 0.0%
August 17, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-27621
First tracked: August 17, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 92%