Description
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.
Published: 2025-03-07
Score: 8.8 High
EPSS: 21.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-7799 Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.
History

Tue, 01 Jul 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Nhairs
Nhairs python Json Logger
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:nhairs:python_json_logger:*:*:*:*:*:*:*:*
Vendors & Products Nhairs
Nhairs python Json Logger

Wed, 12 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 07 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
Description Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.
Title Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Nhairs Python Json Logger
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-07T17:50:28.395Z

Reserved: 2025-03-03T15:10:34.079Z

Link: CVE-2025-27607

cve-icon Vulnrichment

Updated: 2025-03-07T17:50:22.682Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-07T17:15:22.433

Modified: 2025-07-01T16:22:57.830

Link: CVE-2025-27607

cve-icon Redhat

Severity : Important

Publid Date: 2025-03-07T16:18:13Z

Links: CVE-2025-27607 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses