Upsonic operates a focused product line centered on its namesake automation and integration platform, which handles workflow orchestration and data processing tasks. The platform's vulnerability exposure clusters around untrusted deserialization, improper input validation, and path-traversal weaknesses, reflecting risks inherent to systems that accept and process external configuration or user-supplied data flows. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Upsonic over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6278CRITICAL A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of t | Jun 19, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-6279HIGH A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the comp | Jun 19, 2025 | 8.0 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upsonic.
Media articles that mention a CVE ID that affects a product developed by Upsonic — matched by CVE ID, not by vendor name.