VDB

CVE-2025-58367

CVE-2025-58367 PUBLISHED CVSS 10 CRITICAL

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the Delta class constructor, and when combined with a gadget available in DeltaDiff, it can lead to Denial of Service and Remote Code Execution (via insecure Pickle deserialization) exploitation. The gadget available in DeepDiff allows `deepdiff.serialization.SAFE_TO_IMPORT` to be modified to allow dangerous classes such as posix.system, and then perform insecure Pickle deserialization via the Delta class. This potentially allows any Python code to be executed, given that the input to Delta is user-controlled. Depending on the application where DeepDiff is used, this can also lead to other vulnerabilities. This is fixed in version 8.6.1.

EPSS 1.12% · 63.9th percentile

Risk Scores

CVSS 4.0
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS Score
1.12%
63.9th percentile

Affected Products

VendorProductVersions
sepermandeepdiff*
PyPIdeepdiff5.0.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Sep 3, 2025 CVE Published
  • Sep 6, 2025 EPSS Score
  • Sep 6, 2025 Coalition ESS Score
  • Sep 6, 2025 PoC Published
  • Sep 6, 2025 PoC Published
  • Sep 8, 2025 Coalition ESS Score
  • Sep 10, 2025 Coalition ESS Score
  • Sep 10, 2025 PoC Published
  • Sep 11, 2025 Coalition ESS Score
  • Sep 14, 2025 EPSS Score
  • Sep 21, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›