---
id: CVE-2025-70887
aliases:
  - GHSA-p4hh-mq57-gq8x
  - PYSEC-2026-2278
title: >-
  Signify allows a remote attacker to escalate privileges via the signed_data.py
  and the context.py components
summary: >-
  Signify allows a remote attacker to escalate privileges via the signed_data.py
  and the context.py components
severity: high
vendor: signify
product: signify
ecosystem: pip
affected:
  - signify < 0.9.2
patched:
  - signify 0.9.2
published: '2026-03-25'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-p4hh-mq57-gq8x'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-70887'
  - url: 'https://github.com/mtrojnar/osslsigncode/issues/475'
  - url: 'https://github.com/ralphje/signify/issues/60'
  - url: 'https://github.com/mtrojnar/osslsigncode/pull/477'
  - url: >-
      https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8
  - url: 'https://github.com/mtrojnar/osslsigncode/releases/tag/2.11'
  - url: 'https://github.com/ralphje/signify'
tags:
  - osv
  - pip
epss: 0.00343
epssPercentile: 0.25137
ingestedAt: '2026-07-13T18:58:01.202Z'
---

## Overview

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

## Affected packages

- `signify < 0.9.2`

## Remediation

Upgrade to a patched release:

- `signify 0.9.2`
