Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18696 | Upsonic has vulnerability in Pickle Handler component that can lead to deserialization |
Github GHSA |
GHSA-rpfv-46xj-5984 | Upsonic has vulnerability in Pickle Handler component that can lead to deserialization |
Tue, 08 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Upsonic
Upsonic upsonic |
|
| CPEs | cpe:2.3:a:upsonic:upsonic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Upsonic
Upsonic upsonic |
Mon, 23 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. | |
| Title | Upsonic Pickle add_tool cloudpickle.loads deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-23T19:30:05.511Z
Reserved: 2025-06-19T06:52:55.719Z
Link: CVE-2025-6279
Updated: 2025-06-23T16:16:27.017Z
Status : Analyzed
Published: 2025-06-19T21:15:27.203
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-6279
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA