216.73.217.22

CVE-2025-49597

· Published 13/06/2025 20:15 · Modified 13/06/2025 20:15

Labels: CVE-2025-49597 2025-06-13CVE-2025-49597CWE-915[email protected]

Essential information

Published
13/06/2025 20:15
Modified
13/06/2025 20:15
Author
Creator
CVSS
3.9 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called "gadget chain" presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. The problem is patched with Version 1.4.3.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
handcraftedinthealps / goodby-csv cpe:2.3:a:handcraftedinthealps:goodby-csv:*:*:*:*:*:*:*:*

References