CVE-2025-63675

cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netinvent:cryptidy:*:*:*:*:*:python:*:*

History

No history.

Information

Published : 2025-10-31 07:15

Updated : 2025-12-08 13:24


NVD link : CVE-2025-63675

Mitre link : CVE-2025-63675

CVE.ORG link : CVE-2025-63675


JSON object : View

Products Affected

netinvent

  • cryptidy
CWE
CWE-502

Deserialization of Untrusted Data