PT-2025-7251 · Hypercube · Hypercube

Published

2025-02-12

·

Updated

2025-02-12

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: hypercube (affected versions not specified)
Description: The issue allows for remote code execution in web-accessible installations of hypercube. To exploit this, an attacker must make a request against hypercube's endpoints. Standard security practices should be applied.
Recommendations: For hypercube installations that are directly accessible from the Internet, prevent general access from the Internet to mitigate the risk. If the microservice is behind a firewall, no patch is necessary, and no further action is required for users who have used official installation methods. Consider validating the structure of headers passed by the webserver as an additional security measure, but only if the endpoint is publicly exposed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

GHSA-C2P2-HGJG-9R3F

Affected Products

Hypercube