CVE-2025-62647: Rbi Restaurant Brands International Assistant

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path.

Affected products

  • Rbi Restaurant Brands International Assistant: up to and including 2025-09-06

Published 2025-10-17. Last modified 2026-10-08.