Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-27607— Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency

CVSS 8.8 · High EPSS 21.76% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-27607

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency
Source: NVD (National Vulnerability Database)
Vulnerability Description
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
从非可信控制范围包含功能例程
Source: NVD (National Vulnerability Database)
Vulnerability Title
Python JSON Logger 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Python JSON Logger是Nicholas Hairs个人开发者的一个 Python 日志的 JSON 格式化工具。 Python JSON Logger 3.3.0之前版本存在安全漏洞,该漏洞源于缺失的依赖可能导致远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
nhairspython-json-logger >= 3.2.0, < 3.3.0 -

II. Public POCs for CVE-2025-27607

#POC DescriptionSource LinkShenlong Link
1CVE-2025-27607 fixhttps://github.com/Barsug/msgspec-python313-prePOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-27607

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-27607

No comments yet


Leave a comment