CVE-2025-54873
Last modified
CVE-2025-54873 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed integer division allows multiple outputs for certain inputs with only one being valid, and division by zero results are underconstrained. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed integer division allows multiple outputs for certain inputs with only one being valid, and division by zero results are underconstrained. This issue is fixed in risc0-zkvm version 2.2.0 and version 3.0.0 for the risc0-circuit-rv32im and risc0-circuit-rv32im-sys packages.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-54873?
How severe is CVE-2025-54873?
How do I fix CVE-2025-54873?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54868LibreChat is a ChatGPT clone with additional features. In ve…7.5
- CVE-2025-54869FPDI is a collection of PHP classes that facilitate reading …6
- CVE-2025-5487The AutomatorWP – Automator plugin for no-code automations, …7.2
- CVE-2025-54870VTun-ng is a Virtual Tunnel over TCP/IP network. In versions…8.7
- CVE-2025-54871Electron Capture facilitates video playback for screen-shari…7.8
- CVE-2025-54872onion-site-template is a complete, scalable tor hidden servi…8.7
- CVE-2025-54874OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from…9.8
- CVE-2025-54875FreshRSS is a free, self-hostable RSS aggregator. In version…9.8
- CVE-2025-54876The Janssen Project is an open-source identity and access ma…6.9
- CVE-2025-54877Tuleap is an Open Source Suite created to facilitate managem…5.3
- CVE-2025-54878CryptoLib provides a software-only solution using the CCSDS …8.6
- CVE-2025-54879Mastodon is a free, open-source social network server based …7.5
Are you affected by CVE-2025-54873?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
