GHSA-qw34-v3jw-3crvHighCVSS 8.1

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user...

Published
August 10, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.

🔗 References (7)