{"id":"CVE-2025-49597","summary":"handcraftedinthealps goodby-csv Potential Gadget Chain allowing Remote Code Execution","details":"handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called \"gadget chain\" presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. The problem is patched with Version 1.4.3.","aliases":["GHSA-x3c7-22c8-prg7"],"modified":"2026-08-12T03:51:37.302396106Z","published":"2025-06-13T19:51:19.190Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-915"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49597.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49597.json"},{"type":"ADVISORY","url":"https://github.com/handcraftedinthealps/goodby-csv/security/advisories/GHSA-x3c7-22c8-prg7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49597"},{"type":"FIX","url":"https://github.com/handcraftedinthealps/goodby-csv/commit/acd14c6ed85116bb2cb4da35ab62821e5cf54519"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/handcraftedinthealps/goodby-csv","events":[{"introduced":"0"},{"fixed":"acd14c6ed85116bb2cb4da35ab62821e5cf54519"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.4.3"}]}}],"versions":["1.4.2","1.4.1","1.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49597.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"}]}