CVE-2025-61622
Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory
Vexday Risk Score
40Atenção
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 49.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
01 out 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sources. An attacker can craft a data stream that selects pickle-fallback serializer during deserialization, leading to the execution of `pickle.loads`, which is vulnerable to remote code execution.
Users are recommended to upgrade to pyfory version 0.12.3 or later, which has removed pickle fallback serializer and thus fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Apache Software Foundation · Apache ForyQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →