PT-2025-51115 · Tiny Rdm · Tiny Rdm
Zznq
·
Published
2025-12-13
·
Updated
2025-12-13
·
CVE-2025-14606
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
tiny-rdm versions through 1.2.5
Description
A security issue exists in tiny-rdm related to deserialization. The
pickle.loads function within the pickle convert.go file is affected. This can be triggered remotely and requires a high level of complexity to exploit, though exploitation appears difficult. The details of the issue have been publicly disclosed. The project maintainers were notified but have not yet responded.Recommendations
versions prior to 1.2.6
Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tiny Rdm