PT-2025-40450 · Datachain · Datachain

Shcheklein

·

Published

2025-10-02

·

Updated

2025-10-27

·

CVE-2025-61677

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions DataChain versions 0.34.1 and below
Description DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. The library reads serialized objects from environment variables, specifically DATACHAIN METASTORE and DATACHAIN WAREHOUSE, within the loader.py module. This process allows for deserialization of untrusted data. An attacker who can set these environment variables can trigger code execution when the application loads.
Recommendations Update to version 0.34.2 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-61677
GHSA-6PX8-MR29-CJ4R
ZDI-25-965

Affected Products

Datachain