logo

Security Breaches Found in AI-Powered Repair Tool Wondershare RepairIt

ID: c0db30a0-e65d-5acf-9711-b8503fb2d81a

STIX ID: report--c0db30a0-e65d-5acf-9711-b8503fb2d81a

Feed Name: TechRepublic Security

Threat Score
90/100

Date Published: 2025-09-29

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

Trend Micro disclosed two critical flaws in Wondershare RepairIt that left user files, AI models, software binaries, container images, scripts, and source code in unencrypted cloud storage accessible via hardcoded, overly-permissive tokens; because RepairIt automatically pulls and executes AI models from that storage, attackers could swap or tamper with models to achieve arbitrary code execution and widespread supply-chain compromise, and the vendor had not responded to disclosure for five months—users are advised to stop using the product until fixed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.