Executive brief
Red Hat OpenShift AI is a platform used by organizations to build, train, and deploy artificial intelligence models. A security flaw in its TrustyAI component incorrectly grants all authenticated users and service accounts broad visibility into the entire cluster. This allows any user to view information about active workloads (pods), storage volumes, and AI evaluation jobs across all namespaces, potentially exposing sensitive operational metadata.
Technical details
A flaw in the TrustyAI component of Red Hat OpenShift AI results in incorrect privilege assignment via RBAC. The operator creates a ClusterRole (`trustyai-service-operator-lmeval-user-role`) and a ClusterRoleBinding (`trustyai-service-operator-default-lmeval-user-rolebinding`) that targets the `system:authenticated` group. This configuration grants every authenticated user and service account the ability to get, list, and watch pods, persistentvolumeclaims, and lmevaljobs across all namespaces in the cluster. An attacker with basic authenticated access can leverage this to perform reconnaissance and view metadata of workloads they should not have access to. The issue is addressed in OpenShift AI versions 2.25.5 and 3.0.
Affected products
- Red Hat OpenShift AI 2.25 Prior to 2.25.5
- Red Hat OpenShift AI 3.0 Prior to 3.0.0-1762251316
Timeline
- 2025-10-28: disclosed
- 2025-11-12: patched: Patched in RHOAI 3.0 via RHSA-2025:21117
- 2026-04-23: patched: Patched in RHOAI 2.25.5 via RHSA-2026:10184
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2025:21117
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/security/cve/CVE-2025-12103
- https://bugzilla.redhat.com/show_bug.cgi?id=2405966