CVE-2025-61765
Last modified
CVE-2025-61765 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python's `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python's `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package can upgrade to version 5.14.0 or newer, which remove the `pickle` module and use the much safer JSON encoding for inter-server messaging.
Metrics
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-61765?
How severe is CVE-2025-61765?
How do I fix CVE-2025-61765?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6176Scrapy versions up to 2.13.2 are vulnerable to a denial of s…7.5
- CVE-2025-61760Vulnerability in the Oracle VM VirtualBox product of Oracle …7.5
- CVE-2025-61761Vulnerability in the PeopleSoft Enterprise FIN Maintenance M…5.4
- CVE-2025-61762Vulnerability in the PeopleSoft Enterprise FIN Payables prod…6.3
- CVE-2025-61763Vulnerability in Oracle Essbase (component: Essbase Web Plat…8.1
- CVE-2025-61764Vulnerability in the Oracle WebLogic Server product of Oracl…5.3
- CVE-2025-61766Bucket is a MediaWiki extension to store and retrieve struct…6.5
- CVE-2025-61768KUNO CMS is a fully deployable full-stack blog application. …5.1
- CVE-2025-61769Emlog is an open source website building system. A cross-sit…6.1
- CVE-2025-6177Privilege Escalation in MiniOS in Google ChromeOS (16063.45.…7.4
- CVE-2025-61770Rack is a modular Ruby web server interface. In versions pri…7.5
- CVE-2025-61771Rack is a modular Ruby web server interface. In versions pri…7.5
Are you affected by CVE-2025-61765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
