cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
References
Configurations
No configuration.
History
31 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/javiermorales36/cryptidy-analysis - |
31 Oct 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-31 07:15
Updated : 2025-10-31 17:15
NVD link : CVE-2025-63675
Mitre link : CVE-2025-63675
CVE.ORG link : CVE-2025-63675
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
