{"id":"CVE-2025-61765","aliases":["GHSA-g8c6-8fjj-2r4m","PYSEC-2026-1854"],"title":"python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…","summary":"python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","vendor":"python-socketio","product":"python-socketio","ecosystem":"pip","affected":["python-socketio >= 0.8.0, < 5.14.0"],"patched":["python-socketio 5.14.0"],"published":"2025-10-07","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:29.882047738Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g8c6-8fjj-2r4m","references":[{"url":"https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-g8c6-8fjj-2r4m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61765"},{"url":"https://github.com/miguelgrinberg/python-socketio/commit/53f6be094257ed81476b0e212c8cddd6d06ca39a"},{"url":"https://github.com/miguelgrinberg/python-socketio"},{"url":"https://www.bluerock.io/post/cve-2025-61765-bluerock-discovers-critical-rce-in-socket-io-ecosystem"}],"tags":["osv","pip","exploit-available"],"epss":0.00482,"epssPercentile":0.40698,"exploits":{"github":1,"githubRepos":["https://github.com/locus-x64/CVE-2025-61765_PoC"],"checkedAt":"2026-09-23T07:13:37.582Z"},"exploitAvailable":true,"ingestedAt":"2026-07-08T18:25:49.673Z","slug":"CVE-2025-61765","body":"## Overview\n\n### Summary\nA remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications.\n\n### Details\nWhen Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it.\n\nThe vulnerability stems from deserialization of messages using Python's `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python's `__reduce__` method.\n\n### Impact\nThis vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. \n\nSingle-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable.\n\n### Remediation\nIn addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package can upgrade to version 5.14.0 or newer, which remove the `pickle` module and use the much safer JSON encoding for inter-server messaging.\n\n## Affected packages\n\n- `python-socketio >= 0.8.0, < 5.14.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `python-socketio 5.14.0`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4849,"id":"CVE-2025-61765","ts":1788887211820,"field":"exploit_available","old":"false","new":"true"},{"seq":3732,"id":"CVE-2025-61765","ts":1788886328341,"field":"exploit_available","old":"true","new":"false"},{"seq":2577,"id":"CVE-2025-61765","ts":1788883009490,"field":"exploit_available","old":"false","new":"true"},{"seq":1606,"id":"CVE-2025-61765","ts":1788882409786,"field":"exploit_available","old":"true","new":"false"},{"seq":717,"id":"CVE-2025-61765","ts":1788881846772,"field":"exploit_available","old":"false","new":"true"}]}