# CVE-2025-53710

## Summary

- **CVE ID:** CVE-2025-53710
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-653
- **Published:** Dec 18, 2025
- **Last Modified:** Mar 13, 2026

## Description

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands locally.

## Affected Products

- Palantir — com.palantir.compute:compute-service (0.1372.0)
- Palantir — com.palantir.codeassist2:code-assist-proxy (2.1289.0)

## References

- [CNA](https://palantir.safebase.us/?tcuUid=4dbae101-79da-433c-8184-c70b78f4701b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._