Back

CRITICAL

Code Injection Vulnerability in AiDex

Published Apr 15, 2025

Description

In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native functions of the framework used, such as Laravel or Symfony. This execution is achieved by Prompt Injection attacks through the /api/<string-chat>/message endpoint, manipulating the content of the ‘content’ parameter.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the AiDex team in version 1.7.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Apr 15, 2025
Updated Apr 15, 2025
Reserved Apr 14, 2025

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Apr 15, 2025
Updated Apr 15, 2025

GitHub

No data