CVE-2025-59037
Last modified
CVE-2025-59037 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of four of DuckDB's packages that included malicious code to interfere with cryptocoin transactions* According to the npm statistics, nobody has downloaded these packages before they were deprecated. The packages and versions `@duckdb/node-api@1.3.3`, `@duckdb/node-bindings@1.3.3`, `duckdb@1.3.3`, and `@duckdb/duckdb-wasm@1.29.2` were affected. DuckDB immediately deprecated the specific versions, engaged npm support to delete the affected verions, and re-released the node packages with higher version numbers (1.3.4/1.30.0). Users may upgrade to versions 1.3.4, 1.30.0, or a higher version to protect themselves. As a workaround, they may also downgrade to 1.3.2 or 1.29.1.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59037?
How severe is CVE-2025-59037?
How do I fix CVE-2025-59037?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59031Dovecot has provided a script to use for attachment to text …4.3
- CVE-2025-59032ManageSieve AUTHENTICATE command crashes when using literal …7.5
- CVE-2025-59033The Microsoft vulnerable driver block list is implemented as…7.4
- CVE-2025-59034Indico is an event management system that uses Flask-Multipa…4.3
- CVE-2025-59035Indico is an event management system that uses Flask-Multipa…5.4
- CVE-2025-59036Infrahub offers a central hub to manage data, templates, and…5.5
- CVE-2025-59038Prebid.js is a free and open source library for publishers t…8.6
- CVE-2025-59039Prebid Universal Creative (PUC) is a JavaScript API to rende…9.3
- CVE-2025-5904A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It h…8.8
- CVE-2025-59040Tuleap is an Open Source Suite to improve management of soft…4.3
- CVE-2025-59041Claude Code is an agentic coding tool. At startup, Claude Co…9.8
- CVE-2025-59042PyInstaller bundles a Python application and all its depende…7
Are you affected by CVE-2025-59037?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
