Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  Github GHSA | GHSA-97w9-v595-3h5q | cryptidy allows code execution via untrusted data due to pickle.loads | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 31 Oct 2025 07:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
Fri, 31 Oct 2025 07:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py. | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-31T16:44:37.610Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63675
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-31T16:43:16.403Z
 NVD
                        NVD
                    Status : Received
Published: 2025-10-31T07:15:38.283
Modified: 2025-10-31T17:15:48.183
Link: CVE-2025-63675
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.