CVE-2025-60950
MEDIUMAIxBlock - Remote Code Execution via SVG File Upload in Data Preparation
Title source: llmDescription
An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file.
References (3)
Core 3
Core References
Various Sources
https://app.aixblock.io/temp/dbdf9e79_payload1.svg
Scores
CVSS v3
6.1
EPSS
0.0026
EPSS Percentile
17.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Published
Oct 30, 2025
Tracked Since
Feb 18, 2026