CNNVD-202601-1586 Information

CNNVD ID

CNNVD-202601-1586

CVE-2025-62487

  • CNNVD Published: 2026-01-09

Description (Chinese)

Palantir Gotham和Palantir Dossier都是美国Palantir公司的产品。Palantir Gotham是一款可商用、支持人工智能的操作系统。Palantir Dossier是一个写作调查和动态报告工具。 Palantir Gotham和Palantir Dossier存在安全漏洞,该漏洞源于上传的图像未正确标记安全级别,可能导致文件仅添加Everyone组。

Description (English)

Palantir Gotham and Palantir Dossier are products of the United States company Palantir. Palantir Gotham is an operating system that is commercial and supports artificial intelligence. Palantir Dossier is an investigative and dynamic reporting tool. Palantir Gotham and Palantir Dossier had a security loophole, which stemmed from the uploading of images that did not correctly mark the security level, which could lead to only adding the whole group to the file.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Palantir

Published

2026-01-09

Last Modified

2026-02-24

References

https://palantir.safebase.us/?tcuUid=c91a1b4f-72e7-4959-9e2d-3a341e5c7a1f https://access.redhat.com/security/cve/cve-2025-62487

Patch

https://palantir.safebase.us/?tcuUid=c91a1b4f-72e7-4959-9e2d-3a341e5c7a1f

Share on: