logo

Vulnerability in popular AI developer could ‘shut down essentially everything you own’ 

ID: f78f1ec3-8f92-514f-b6fc-b4f89967369e

STIX ID: report--f78f1ec3-8f92-514f-b6fc-b4f89967369e

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2025-01-29

Date Updated: 2026-04-21

Author: djohnson

...
...

Noma researchers discovered a critical RCE flaw in Lightning.AI's platform caused by a hidden JavaScript "command" URL parameter that could enable attackers to execute arbitrary code, gain root-level access to cloud studios, access AWS metadata and credentials, and move laterally; the issue (CVSS 9.4 per Noma) was reported Oct 14, 2024 and patched by Oct 25, 2024, with Lightning.AI stating no evidence of unauthorized access and additional security hardening applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.