External risk intelligence

GT Edge AI Community Edition JSON Injection Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-63665

The vulnerability exists in a product's prompt window, a component typically found in web-based AI interfaces or applications. Such interfaces are commonly deployed as web applications or services reachable from the public internet to allow user interaction, making the vulnerable surface likely to be exposed.

Code Injection

Gtedge Gt Edge Ai

before 2.0.12

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security vulnerability found in GT Edge AI Community Edition. Attackers can exploit this flaw to run their own code by sending specially crafted data through the prompt window. This could allow unauthorized access and control over affected systems. The main concern is confirming if our environment uses the specific version of this AI technology, as the impact on our operations is not yet fully understood.

  • Flaw allows unauthenticated code execution via crafted input.
  • Critical vulnerability in AI product warrants attention.
  • Confirm relevance and exposure to this AI technology.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted JSON payload to the application's Prompt window. This action can lead to the execution of arbitrary code on the affected system.

  • No authentication or privileges required.
  • Injecting JSON into the Prompt window.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code by submitting a specially crafted JSON payload to the prompt window of the GT Edge AI Community Edition. This could impact the confidentiality, integrity, and availability of the affected system.

  • System code execution.
  • Via crafted JSON payload.
  • Full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability, enabling arbitrary code execution through crafted JSON payloads, likely impacts applications utilizing GT Edge AI Community Edition. Owners of these AI-driven applications, potentially integrated into web services, should first identify all deployments of the affected technology. The next step involves assessing business criticality and external reachability to prioritize remediation efforts, possibly involving coordination with the vendor or implementing compensating controls if immediate patching is not feasible.

  • Application owners should drive remediation.
  • Verify external reachability and business criticality.
  • Plan and coordinate updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is GT Edge AI Community Edition?

GT Edge AI is a software platform designed for artificial intelligence tasks. The Community Edition is a version often used by developers and organizations to build or interact with AI models through a graphical interface, specifically featuring a Prompt window where users input data for the system to process.

What does CWE-94 mean for CVE-2025-63665?

CWE-94 refers to Improper Control of Generation of Code. In this CVE, it means the application fails to properly filter input, allowing an attacker to supply their own instructions disguised as data. Because the system treats this malicious input as executable commands, it can be tricked into running code chosen by the attacker.

How do I trigger this vulnerability?

An attacker exploits this by sending a specially crafted JSON payload directly into the application's Prompt window. Simply using the application for standard AI queries with typical text inputs will not trigger the bug; the vulnerability requires a specific, structured JSON format designed to bypass the application's intended logic.

Is my GT Edge AI deployment at risk?

Halo Surface Signal indicates this vulnerability is likely exposed if your AI interface is reachable from the public internet. If the system is hosted internally and restricted to a private network, the risk is lower, but you should still assess whether any external services might reach it.

What steps should I take if I use this software?

First, identify all instances of GT Edge AI Community Edition in your environment to check the version number. If you are running any version before 2.0.12, you are affected. Prioritize updating the software to version 2.0.12 or later as soon as possible to secure the Prompt window against malicious payload injection.

References