CVE-2025-31951: Hcl Bigfix Runbookai

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

Affected products

  • Hcl Bigfix Runbookai: version 11.2 only

Published 2026-05-06. Last modified 2026-10-07.