CVE-2025-61765EPSS p39.7%
CVE-2025-61765CVE-2025-61765
Description
python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python's `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deser
Scoring
| CVSS | 6.4 () |
| Vector | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L |
| EPSS | 0.48% probability of exploitation · percentile 39.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |