CVE-2025-52643

Severity CVSS v4.0:
Pending analysis
Type:
CWE-693 Protection Mechanism Failure
Publication date:
16/03/2026
Last modified:
25/04/2026

Description

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:* 2.0.0 (including) 2.1.2 (excluding)