Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-27607

8.8 · HIGH
Published Mar 7, 2025 nhairs CWE-829 EPSS 1.96% (79th pctl)

Overview

CVE-2025-27607 is a high-severity vulnerability affecting nhairs python_json_logger. It was published on March 7, 2025 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.

Remediation

Check the references section for vendor advisories and patches from nhairs. Update python_json_logger to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
nhairs python_json_logger >= 0, < 3.3.0 Affected

Frequently Asked Questions

What is CVE-2025-27607?

CVE-2025-27607 is a high-severity vulnerability affecting nhairs python_json_logger. It was published on March 7, 2025 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2025-27607?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2025-27607?

Check the references section for vendor advisories and patches from nhairs. Update python_json_logger to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-27607?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-27607 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.