Executive brief
IBM Engineering AI Hub is a platform used for managing AI-driven engineering lifecycles. A security flaw in this software allows attackers to trick users into visiting malicious websites by using specially crafted links that appear to be legitimate. This could be used in phishing campaigns to steal user credentials or deliver malware by exploiting the trust users have in the corporate domain.
Technical details
An open redirect vulnerability (CWE-601) exists in IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0. The application fails to properly validate user-supplied input used in redirection URLs, allowing a remote, unauthenticated attacker to craft a link that redirects a victim to an external, untrusted domain. Exploitation requires a user to click the malicious link (User Interaction). While the primary impact is facilitating phishing attacks, the vulnerability is rated medium severity with a CVSS score of 4.3. The issue is addressed in IBM Engineering AI Hub version 1.3.0.
Affected products
- IBM Engineering AI Hub 1.0.0, 1.1.0, 1.2.0
Timeline
- 2026-07-17: advisory: IBM published the security bulletin and NVD record.
- 2026-07-17: patched: Vulnerability addressed in version 1.3.0.