CVE-2025-52645

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
16/03/2026
Last modified:
25/04/2026

Description

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:* 2.0.0 (including) 2.1.2 (excluding)