MEDIUM6.9
PYSEC-2026-1282
cryptidy allows code execution via untrusted data due to pickle.loads
Details
cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/cryptidy
Introduced in:
0No fixed version published yet for cryptidy (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-63675[ADVISORY]
- https://github.com/javiermorales36/cryptidy-analysis[WEB]
- https://github.com/netinvent/cryptidy[PACKAGE]
- https://github.com/netinvent/cryptidy/blob/cebc9ffd54cc20679d15a1a43ca9a5da645b0c58/cryptidy/symmetric_encryption.py#L220-L238[WEB]
- https://pypi.org/project/cryptidy[PACKAGE]
- https://github.com/advisories/GHSA-97w9-v595-3h5q[ADVISORY]