Skip to content

CVE-2025-50817 #650

Description

@MallocArray

Trivy scanner is now detecting future as having a High severity CVE
https://avd.aquasec.com/nvd/2025/cve-2025-50817/

Will this be addressed in an update to this module?

Activity

  1. M1ndas commented on Aug 19, 2025

    @M1ndas

    Relates to: #268

  2. kishorchouhan commented on Aug 29, 2025

    @kishorchouhan

    @edschofield We got below dependabot for future package. When can we expect this to be solved. TIA

    Image
  3. fried commented on Sep 3, 2025

    @fried

    This CVE is beyond ridiculous. High severity is laughable. It boils down to "If you have access to my code you can execute arbitrary code".

    test is in the standard lib, the standard lib has many modules and any of them could be "exploited" in this exact way. The only ones safe are builtins modules like "sys".

    If this is an expliot, then every piece of python code ever written that imports from the stdlib in any capacity is also exploited. Basic python import semantics is not a CVE. The exploit wouldn't even be in this project it would be in cpython itself. The only problem that project is active and everyone would realize how insane the CVE was and it would get redacted

  4. iamleot commented on Sep 4, 2025

    @iamleot

    Thanks @fried for sharing context.

    I have requested this CVE to be rejected via MITRE CVE Request web form (CVE Request 1919432 for Update Published CVE) and linked both the standard Python documentation and this discussion.

  5. M1ndas commented on Sep 16, 2025

    @M1ndas

    Any updates to the CVE update request, @iamleot ?

  6. iamleot commented on Sep 16, 2025

    @iamleot

    @MindaugasBernatavicius no, I have not received any updates.

  7. iamleot commented on Sep 26, 2025

    @iamleot

    Hello, JFTR CVE-2025-50817 was marked as Disputed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions