A Vulnerability in Lightning AI Studio Resulted in RCE through Concealed URL Element
Experts in online security have exposed a severe weakness in the development platform of Lightning AI Studio that, if effectively taken advantage of, could lead to remote code execution. The vulnerability, assessed with a CVSS score of 9.4, permits “malicious actors to potentially execute unauthorized commands with elevated privileges” by manipulating a concealed URL parameter, as reported by the cybersecurity company Noma.
