CVE-2025-61622 is a critical deserialization of untrusted data vulnerability affecting pyfory versions 0.12.0 through 0.12.2, and legacy versions 0.1.0 through 0.10.3. An attacker can craft a malicious data stream that forces the use of a vulnerable pickle-fallback serializer, leading to arbitrary code execution on systems that process untrusted pyfory serialized data. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion, and users are strongly advised to upgrade to pyfory version 0.12.3 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, <= 0.10.3CPE matchmatch criteria | cpe:2.3:a:apache:fory:*:*:*:*:*:*:*:* | ||
>= 0.12.0, <= 0.12.2CPE matchmatch criteria | cpe:2.3:a:apache:fory:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.