← All research

CVE-2025-63665

Arbitrary Code Execution via JSON Injection

01Record

IdentifierCVE-2025-63665
ProjectGT Edge AI Platform
Component/chat
CWECWE-94
CVSS9.8
Disclosed2025-12-19
WriteupLink

02Detail

Description: JSON injection vulnerability in the /chat component allows attackers to execute arbitrary code by injecting crafted JSON payloads into the prompt window, leading to system prompt disclosure and access to previous chat history.

Impact: Code Execution, Information Disclosure

Discovered by Peyton Kennedy (p80n), Richard Medlin.