CVE-2025-52643

MEDIUM

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files.

Scores

CVSS v3 4.7
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (2)
HCL/AION 2.0
hcltech/aion 2.0 - 2.1.2
Published Mar 16, 2026
Tracked Since Mar 16, 2026