PT-2025-26242 · Upsonic · Upsonic

Resp4Ss

·

Published

2025-06-19

·

Updated

2025-06-20

·

CVE-2025-6279

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Upsonic versions up to 0.55.6
Description A critical issue has been found in the Pickle Handler component of Upsonic, affecting the cloudpickle.loads function. This issue leads to deserialization. The exploit has been disclosed to the public and may be used.
Recommendations For versions up to 0.55.6, consider disabling the cloudpickle.loads function in the Pickle Handler component as a temporary workaround until a patch is available. Restrict access to the /tools/add tool file to minimize the risk of exploitation.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-6279
GHSA-RPFV-46XJ-5984
PYSEC-2025-68

Affected Products

Upsonic