Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7799 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0. |
Tue, 01 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nhairs
Nhairs python Json Logger |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:nhairs:python_json_logger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nhairs
Nhairs python Json Logger |
Wed, 12 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 07 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0. | |
| Title | Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-07T17:50:28.395Z
Reserved: 2025-03-03T15:10:34.079Z
Link: CVE-2025-27607
Updated: 2025-03-07T17:50:22.682Z
Status : Analyzed
Published: 2025-03-07T17:15:22.433
Modified: 2025-07-01T16:22:57.830
Link: CVE-2025-27607
OpenCVE Enrichment
No data.
EUVD