CVE-2025-52643: Hcltech Aion

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files.

Affected products

  • Hcltech Aion: from 2.0.0, before 2.1.2 (fixed in 2.1.2)

Published 2026-03-16. Last modified 2026-06-17.