๐Ÿ” CVE Alert

CVE-2025-52643

MEDIUM 4.7

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files.

Vendor hcl
Product aion
Published Mar 16, 2026
Last Updated Mar 16, 2026
Stay Ahead of the Next One

Get instant alerts for hcl aion

Be the first to know when new medium vulnerabilities affecting hcl aion are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

HCL / AION
2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.hcl-software.com: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410