CVE-2025-49597: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in handcraftedinthealps goodby-csv

Low
VulnerabilityCVE-2025-49597cvecve-2025-49597cwe-915
Published: Fri Jun 13 2025 (06/13/2025, 19:51:19 UTC)
Source: CVE Database V5
Vendor/Project: handcraftedinthealps
Product: goodby-csv

Description

handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called "gadget chain" presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. The problem is patched with Version 1.4.3.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-06-06T15:44:21.557Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 684c8450a8c921274380e66b

Added to database: 6/13/2025, 8:04:32 PM

Last updated: 6/13/2025, 8:05:33 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats