CVE-2025-53710
Unknown
Unknown - Not Provided
Access Control Bypass via Command Injection in Foundry Container Service
Publication date: 2025-12-18
Last updated on: 2025-12-18
Assigner: Palantir Technologies
Description
Description
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands locally.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palantir | foundry_container_service | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-653 | The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions. |