VYPR

Uptrain

by Uptrain AI

CVEs (4)

  • CVE-2025-27621HigAug 17, 2026
    risk 0.50cvss epss

    UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the username is also used as the default API key. The UpTrain backend also has an open…

  • CVE-2025-27772HigAug 17, 2026
    risk 0.48cvss epss

    UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid…

  • CVE-2025-27771HigAug 17, 2026
    risk 0.48cvss epss

    UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid…

  • CVE-2025-27770HigAug 17, 2026
    risk 0.48cvss epss

    UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid…