CVE-2025-63665
Arbitrary Code Execution via JSON Injection
01Record
| Identifier | CVE-2025-63665 |
|---|---|
| Project | GT Edge AI Platform |
| Component | /chat |
| CWE | CWE-94 |
| CVSS | 9.8 |
| Disclosed | 2025-12-19 |
| Writeup | Link |
02Detail
Description: JSON injection vulnerability in the /chat component allows attackers to execute arbitrary code by injecting crafted JSON payloads into the prompt window, leading to system prompt disclosure and access to previous chat history.
Impact: Code Execution, Information Disclosure
Discovered by Peyton Kennedy (p80n), Richard Medlin.