An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
References
| Link | Resource |
|---|---|
| https://github.com/mtrojnar/osslsigncode/issues/475 | Not Applicable |
| https://github.com/mtrojnar/osslsigncode/pull/477 | Not Applicable |
| https://github.com/mtrojnar/osslsigncode/releases/tag/2.11 | Not Applicable |
| https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8 | Patch |
| https://github.com/ralphje/signify/issues/60 | Issue Tracking |
Configurations
History
01 Apr 2026, 13:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mtrojnar/osslsigncode/issues/475 - Not Applicable | |
| References | () https://github.com/mtrojnar/osslsigncode/pull/477 - Not Applicable | |
| References | () https://github.com/mtrojnar/osslsigncode/releases/tag/2.11 - Not Applicable | |
| References | () https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8 - Patch | |
| References | () https://github.com/ralphje/signify/issues/60 - Issue Tracking | |
| First Time |
Ralphje
Ralphje signify |
|
| CPE | cpe:2.3:a:ralphje:signify:*:*:*:*:*:python:*:* |
27 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CWE | CWE-269 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
25 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 19:16
Updated : 2026-04-01 13:59
NVD link : CVE-2025-70887
Mitre link : CVE-2025-70887
CVE.ORG link : CVE-2025-70887
JSON object : View
Products Affected
ralphje
- signify
CWE
CWE-269
Improper Privilege Management
