PT-2025-36336 · Deepdiff · Deepdiff
Diogotcorreia
·
Published
2025-09-03
·
Updated
2025-09-28
·
CVE-2025-58367
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
DeepDiff versions 5.0.0 through 8.6.0
Description
DeepDiff is a Python project for deep difference and search of data. Versions 5.0.0 through 8.6.0 are susceptible to class pollution through the
Delta class constructor. When combined with a gadget in DeltaDiff, this can lead to Denial of Service and Remote Code Execution via insecure Pickle deserialization. The gadget allows modification of deepdiff.serialization.SAFE TO IMPORT to permit dangerous classes, such as posix.system, enabling the execution of arbitrary Python code through user-controlled input to the Delta class.Recommendations
Update to DeepDiff version 8.6.1 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deepdiff