A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls to the history service, an attacker can view, delete, or inject arbitrary history entries, including misleading or malicious commands. This can be used to deceive another user into executing harmful actions, posing a risk of privilege misuse or unauthorized command execution through social engineering.
History

Mon, 22 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/o:redhat:enterprise_linux:10.0
References

Mon, 22 Sep 2025 08:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls to the history service, an attacker can view, delete, or inject arbitrary history entries, including misleading or malicious commands. This can be used to deceive another user into executing harmful actions, posing a risk of privilege misuse or unauthorized command execution through social engineering.
Title Rhel-lightspeed: improper access control in lightspeed history management allows local privilege manipulation
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-284
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-09-22T08:04:39.673Z

Updated: 2025-09-25T08:41:02.931Z

Reserved: 2025-06-10T06:06:36.103Z

Link: CVE-2025-5962

cve-icon Vulnrichment

Updated: 2025-09-22T15:48:44.799Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-22T08:15:34.533

Modified: 2025-09-22T21:22:33.590

Link: CVE-2025-5962

cve-icon Redhat

No data.