PT-2025-25443 · Unknown · Goodby-Csv

Mcdruid

·

Published

2025-06-13

·

Updated

2025-06-16

·

CVE-2025-49597

CVSS v3.1

3.9

Low

VectorAV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions goodby-csv versions prior to 1.4.3
Description The issue concerns an insecure deserialization vulnerability in the goodby-csv library, which can be used as part of a "gadget chain" to achieve remote code execution if an application deserializes untrusted data due to another vulnerability. This presents no direct threat but is a vector that can be exploited.
Recommendations For versions prior to 1.4.3, update to version 1.4.3 to resolve the issue. As a temporary workaround, consider restricting the use of the goodby-csv library in applications that deserialize untrusted data to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-49597
GHSA-X3C7-22C8-PRG7

Affected Products

Goodby-Csv