Database/AI/ML frameworks & serving
Red Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromise
CVSS 9.9CVE-2025-10725AI/ML frameworks & servingcurated
Impact
A low-privileged data-scientist account can escalate to full cluster compromise
Who can reach it
Notebook user inside the managed AI platform
What to do
Patch the platform. Direct tenant→provider escalation on a managed GPU platform
References
Related entries
- BentoML (file upload): SSRF in the file-upload pathCVE-2025-54381 · BentoML (file upload)Critical
- OpenShift AI MaaS API: any in-cluster pod forges identity headers to impersonate tenantsCVE-2026-14450 · Red Hat OpenShift AI MaaS API (Kuadrant AuthPolicy gateway)Critical
- NVIDIA OpenShell: incomplete input denylist in the sandbox provisioning API allows code executionCVE-2026-65083 · NVIDIA OpenShell (sandbox provisioning API)Critical
- NVIDIA OpenShell: sandbox escape lets confined code run outside the sandboxCVE-2026-65093 · NVIDIA OpenShell (agent sandbox confinement)Critical
- MCPHub: any authenticated user can register an MCP server and run arbitrary commands as the service userCVE-2026-79748 · MCPHub (POST /api/servers, PUT /api/servers/:name)Critical
- GitLab AI Gateway: crafted Duo flow config escapes the prompt template sandbox into command executionCVE-2026-90970 · GitLab AI Gateway (Duo Agent Platform flow configuration)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.