A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. | |
Title | Upsonic Pickle add_tool cloudpickle.loads deserialization | |
Weaknesses | CWE-20 CWE-502 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-19T21:00:14.350Z
Updated: 2025-06-19T21:00:14.350Z
Reserved: 2025-06-19T06:52:55.719Z
Link: CVE-2025-6279

No data.

Status : Received
Published: 2025-06-19T21:15:27.203
Modified: 2025-06-19T21:15:27.203
Link: CVE-2025-6279

No data.