CVE-2025-31951CWE-351CWE-451CWE-77

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability

High · published May 6, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
15.9
In the wild
Unconfirmed
What it is

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00247 · 15.9th percentile
Weaknesses
CWE-351 · Insufficient Type Distinction; CWE-451 · User Interface (UI) Misrepresentation of Critical Information; CWE-77 · Improper Neutralization of Special Elements used in a Command ('Command Injection')
Published
2026-05-06T11:47Z
EPSS history
Timeline
  • 06 MAY 11:47Z
    HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
    cvelistv5