Executive brief
A security vulnerability has been identified in the Red Hat Lightspeed history service, a component of the command-line assistant used to interact with AI-driven retrieval systems. An unauthorized user on a shared system could view, delete, or modify the chat history of other users. This could lead to the exposure of sensitive information or the injection of malicious commands that trick other users into performing harmful actions.
Technical details
An improper access control vulnerability (CWE-284) exists in the Lightspeed history service component of the command-line-assistant package. The flaw stems from insufficient validation of inter-process communication (IPC) calls, which allows a local, unprivileged user to interact with the history service of other users on the same host. By abusing these IPC calls, an attacker can read, delete, or inject arbitrary entries into another user's chat history. This manipulation can be used to stage social engineering attacks by inserting misleading or malicious commands into the history, which a victim might later execute. Patches are available for Red Hat Enterprise Linux 9 and 10.
Affected products
- Red Hat Red Hat Enterprise Linux 9 command-line-assistant < 0.3.1-6.el9_6
- Red Hat Red Hat Enterprise Linux 10 command-line-assistant < 0.3.1-6.el10_0
- Red Hat Red Hat In-Vehicle Operating System 1 command-line-assistant
Timeline
- 2025-09-22: disclosed
- 2025-09-22: advisory: Red Hat published RHSA-2025:16345 and RHSA-2025:16346
- 2025-09-22: patched