Executive brief
UpTrain is an open-source platform for evaluating and improving generative AI applications. The `/add_prompts` endpoint uses unsafe code evaluation on user-supplied parameters, allowing authenticated users to execute arbitrary code on the host system. An attacker with valid authentication can gain control of the UpTrain container or host, potentially compromising the entire application and any data it processes.
Technical details
The vulnerability is a code injection flaw in the `/add_prompts` endpoint (GHSL-2024-200 / CVE-2025-27771). The endpoint accepts `checks` and `metadata` form parameters and passes them directly to Python's `eval()` function without validation or sanitization, allowing arbitrary Python code execution. The attack requires network access to the UpTrain API and a valid authentication method (API key or similar). An authenticated attacker can inject malicious Python code through these parameters to execute arbitrary commands in the context of the UpTrain process. As of publication, no patch is available; the project appears to be unmaintained as of March 2025.
Affected products
- UpTrain UpTrain 0.7.1 and prior
Timeline
- 2024-09-05: disclosed: Issue opened in repo
- 2026-08-08: advisory: GHSL security advisory published
- 2026-08-17: advisory: NVD entry published