CVE-2025-53710 Details
Description
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands locally.
A vulnerability in Palantir Foundry Container Service allowed pods in the same namespace to communicate with each other, bypassing access controls. This issue arose from a product misconfiguration in certain deployment types, enabling direct pod-to-pod communication. Compounding the problem, a vulnerable endpoint in the Foundry Container Service executed user-controlled commands locally without proper access control, potentially leading to privilege escalation or unauthorized actions across pods.
The vulnerability has been addressed by enforcing stricter network boundaries between pods, updating the Foundry Container Service endpoint to listen only on localhost, implementing authentication checks on the affected endpoint, and releasing fixed versions of the compute-service and code-assist-proxy.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 18, 2025CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://palantir.safebase.us/?tcuUid=4dbae101-79da-433c-8184-c70b78f4701b | [email protected] | Permission RequiredVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-653 | Improper Isolation or Compartmentalization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Palantir Foundry Container Service | All versions |
CPE
Remediation
| |
| Palantir Control Panel | All versions |
CPE
Remediation
| |
| Palantir gotham-default-apps-bundle | All versions |
CPE
Remediation
| |
| Palantir dossier-app | All versions |
CPE
Remediation
| |
| Palantir stencil-app-bundle | All versions |
CPE
Remediation
| |
| Palantir artifacts | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | New CVE Received | [email protected] |
Volerion