Command Injection Vulnerability in TrustyAI Explainability Toolkit by Red Hat
CVE-2025-6193
5.9MEDIUM
What is CVE-2025-6193?
A command injection vulnerability has been identified in the TrustyAI Explainability Toolkit, allowing arbitrary commands to be executed in the terminal of an LMEvalJob pod. This issue arises when users with sufficient permissions deploy a crafted LMEvalJob custom resource (CR), leading to the potential execution of unauthorized commands. Regular updates and assessments are crucial for safeguarding against this type of vulnerability.