CVE-2025-6193: Red Hat Openshift Ai 2.16
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.
Affected products
- Red Hat Red Hat Openshift Ai 2.16: before 1774285579 (fixed in 1774285579)
- Red Hat Red Hat Openshift Ai Rhoai
Published 2025-06-20. Last modified 2026-10-09.