PT-2025-39961 · Apache · Apache Fory
Bugbunny_Ai
·
Published
2025-09-30
·
Updated
2026-05-30
·
CVE-2025-61622
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pyfory versions 0.12.0 through 0.12.2
pyfury versions 0.1.0 through 0.10.3
Description
Deserialization of untrusted data in Python allows arbitrary code execution. An application is susceptible if it reads serialized data from untrusted sources. An attacker can craft a data stream that triggers the pickle-fallback serializer during deserialization, leading to the execution of the
pickle.loads() function, which enables remote code execution.Recommendations
Upgrade pyfory to version 0.12.3 or later.
Upgrade pyfury to pyfory version 0.12.3 or later.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Fory