PT-2025-36336 · Deepdiff · Deepdiff

Diogotcorreia

·

Published

2025-09-03

·

Updated

2025-09-28

·

CVE-2025-58367

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions DeepDiff versions 5.0.0 through 8.6.0
Description DeepDiff is a Python project for deep difference and search of data. Versions 5.0.0 through 8.6.0 are susceptible to class pollution through the Delta class constructor. When combined with a gadget in DeltaDiff, this can lead to Denial of Service and Remote Code Execution via insecure Pickle deserialization. The gadget allows modification of deepdiff.serialization.SAFE TO IMPORT to permit dangerous classes, such as posix.system, enabling the execution of arbitrary Python code through user-controlled input to the Delta class.
Recommendations Update to DeepDiff version 8.6.1 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-58367
GHSA-MW26-5G2V-HQW3
OPENSUSE-SU-2025:15536-1
SUSE-SU-2025:03127-1

Affected Products

Deepdiff