CVE-2025-58367 is a critical vulnerability affecting DeepDiff versions 5.0.0 through 8.6.0, allowing for class pollution via the Delta class constructor. This can lead to Denial of Service and Remote Code Execution through insecure Pickle deserialization, potentially enabling arbitrary Python code execution if user-controlled input is passed to Delta. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no user interaction or privileges, and has a high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low immediate threat but a high potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Seperman | Deepdiff | >= 5.0.0, < 8.6.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.