CVE-2025-70887

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
Configurations

Configuration 1 (hide)

cpe:2.3:a:ralphje:signify:*:*:*:*:*:python:*:*

History

01 Apr 2026, 13:59

Type Values Removed Values Added
References () https://github.com/mtrojnar/osslsigncode/issues/475 - () https://github.com/mtrojnar/osslsigncode/issues/475 - Not Applicable
References () https://github.com/mtrojnar/osslsigncode/pull/477 - () https://github.com/mtrojnar/osslsigncode/pull/477 - Not Applicable
References () https://github.com/mtrojnar/osslsigncode/releases/tag/2.11 - () https://github.com/mtrojnar/osslsigncode/releases/tag/2.11 - Not Applicable
References () https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8 - () https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8 - Patch
References () https://github.com/ralphje/signify/issues/60 - () https://github.com/ralphje/signify/issues/60 - Issue Tracking
First Time Ralphje
Ralphje signify
CPE cpe:2.3:a:ralphje:signify:*:*:*:*:*:python:*:*

27 Mar 2026, 20:16

Type Values Removed Values Added
Summary
  • (es) Un problema en ralphje Signify antes de la v.0.9.2 permite a un atacante remoto escalar privilegios a través de los componentes signed_data.py y context.py
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

25 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 19:16

Updated : 2026-04-01 13:59


NVD link : CVE-2025-70887

Mitre link : CVE-2025-70887

CVE.ORG link : CVE-2025-70887


JSON object : View

Products Affected

ralphje

  • signify
CWE
CWE-269

Improper Privilege Management