CVE-2025-6193 Information
Jun 21, 2025
cve
Description
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod’s terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Reference
https://access.redhat.com/security/cve/CVE-2025-6193 https://bugzilla.redhat.com/show_bug.cgi?id=2374032
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.9
Related CNNVD
CNNVD-202506-2780 (Published: 2025-06-20)
Share on: