CVE-2025-62703 is a remote code execution (RCE) vulnerability affecting Fugue versions 0.9.2 and prior. The vulnerability stems from insecure deserialization of Python pickle data within the FlaskRPCServer component, specifically in the _decode() function, allowing an attacker to execute arbitrary code on the server. This vulnerability is rated High severity with a CVSS score of 8.8, indicating a critical risk. It has a low attack complexity and requires no user interaction, as an attacker can exploit it over the network (AV:A). Successful exploitation can lead to complete compromise of confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting it is not widely known or actively targeted at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.1CPE matchmatch criteria | cpe:2.3:a:fugue-project:fugue:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.