{"id":"CVE-2025-70887","aliases":["GHSA-p4hh-mq57-gq8x","PYSEC-2026-2278"],"title":"Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components","summary":"Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components","severity":"high","vendor":"signify","product":"signify","ecosystem":"pip","affected":["signify < 0.9.2"],"patched":["signify 0.9.2"],"published":"2026-03-25","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-p4hh-mq57-gq8x","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70887"},{"url":"https://github.com/mtrojnar/osslsigncode/issues/475"},{"url":"https://github.com/ralphje/signify/issues/60"},{"url":"https://github.com/mtrojnar/osslsigncode/pull/477"},{"url":"https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8"},{"url":"https://github.com/mtrojnar/osslsigncode/releases/tag/2.11"},{"url":"https://github.com/ralphje/signify"}],"tags":["osv","pip"],"epss":0.00343,"epssPercentile":0.27947,"ingestedAt":"2026-07-13T18:58:01.202Z","slug":"CVE-2025-70887","body":"## Overview\n\nAn issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components\n\n## Affected packages\n\n- `signify < 0.9.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `signify 0.9.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}