CVE-2025-5174
Last modified
CVE-2025-5174 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.0 is able to address this issue. The patch is identified as 14b4cae704a0bb4eb6723e238f25382d847a1917. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Erdogant | Pypickle | < 2.0.0 |
References
- https://github.com/erdogant/pypickle/issues/2Exploit, Issue Tracking, Vendor Advisory
- https://github.com/erdogant/pypickle/issues/2#issuecomment-2889146579Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.310262Permissions Required, VDB Entry
- https://vuldb.com/?id.310262Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.579157Third Party Advisory, VDB Entry
- https://github.com/erdogant/pypickle/issues/2Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5174?
How severe is CVE-2025-5174?
How do I fix CVE-2025-5174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-51726CyberGhostVPNSetup.exe (Windows installer) is signed using t…8.4
- CVE-2025-5173A vulnerability has been found in HumanSignal label-studio-m…7.8
- CVE-2025-51733Cross-Site Request Forgery (CSRF) vulnerability in HCL Techn…5.5
- CVE-2025-51734Cross-site scripting (XSS) vulnerability in HCL Technologies…5.4
- CVE-2025-51735CSV formula injection vulnerability in HCL Technologies Ltd.…7.5
- CVE-2025-51736File upload vulnerability in HCL Technologies Ltd. Unica 12.…6.3
- CVE-2025-51741An issue was discovered in Veal98 Echo Open-Source Community…7.5
- CVE-2025-51742An issue was discovered in jishenghua JSH_ERP 2.3.1. The /ma…9.8
- CVE-2025-51743An issue was discovered in jishenghua JSH_ERP 2.3.1. The /ma…9.8
- CVE-2025-51744An issue was discovered in jishenghua JSH_ERP 2.3.1. The /us…9.8
- CVE-2025-51745An issue was discovered in jishenghua JSH_ERP 2.3.1. The /ro…9.8
- CVE-2025-51746An issue was discovered in jishenghua JSH_ERP 2.3.1. The /se…9.8
Are you affected by CVE-2025-5174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
