{"id":"CVE-2025-62193","summary":"NOAA PMEL Live Access Server (LAS) PyFerret command injection","details":"Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tmap.las.filter.RequestInputFilter.java'  from 2025-09-24.","modified":"2026-08-12T15:14:23.062076Z","published":"2026-01-15T16:44:15.708Z","database_specific":{"cna_assigner":"cisa-cg","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62193.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8"},{"last_affected":"8"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/NOAA-PMEL/LAS/tree/main"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62193.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62193"},{"type":"ADVISORY","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-015-01.json"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-62193"},{"type":"FIX","url":"https://github.com/NOAA-PMEL/LAS/blob/main/README.md"},{"type":"FIX","url":"https://github.com/NOAA-PMEL/LAS/commit/de5f9237bfd4ac5085bcc49a6e30bbc9507ddb29"},{"type":"FIX","url":"https://github.com/NOAA-PMEL/LAS/commit/e69afb1898ae7e69f3e047513fc1e5570373912b"},{"type":"FIX","url":"https://github.com/NOAA-PMEL/LAS/compare/b4b7306..de5f923"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/noaa-pmel/las","events":[{"introduced":"0"},{"fixed":"de5f9237bfd4ac5085bcc49a6e30bbc9507ddb29"},{"fixed":"e69afb1898ae7e69f3e047513fc1e5570373912b"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v8.6.20","v8.6.19","v8.6.12a","v8.6.12","v8.6.11","v8.6.7","v8.6.3","v8.6.1","v8.6","v8.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62193.json","vanir_signatures_modified":"2026-08-12T15:14:23Z","vanir_signatures":[{"target":{"file":"JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java","function":"doFilter"},"deprecated":false,"digest":{"function_hash":"264110938858644081626382572019043999149","length":4087},"id":"CVE-2025-62193-3935a9d6","signature_type":"Function","signature_version":"v1","source":"https://github.com/noaa-pmel/las/commit/e69afb1898ae7e69f3e047513fc1e5570373912b"},{"id":"CVE-2025-62193-8d76a6df","signature_type":"Function","signature_version":"v1","source":"https://github.com/noaa-pmel/las/commit/de5f9237bfd4ac5085bcc49a6e30bbc9507ddb29","target":{"function":"doFilter","file":"JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java"},"deprecated":false,"digest":{"function_hash":"324565465957741215688029378028800636120","length":4338}},{"source":"https://github.com/noaa-pmel/las/commit/de5f9237bfd4ac5085bcc49a6e30bbc9507ddb29","target":{"file":"JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java"},"deprecated":false,"digest":{"line_hashes":["206901422374408798000118277334840509130","30605514444261962193355705441431143325","294555619782481844433490037256909079572","33961252826728506418109507157165892741","288093082721647599220593744418518299052","163177821530609106539900095409214711728","15139395908995812337620342125063960224","333999602153991819968531649721441315203","79771935827876963762736981009679029044","82628333836079610175111370152475825590","22519786985753355745276078895911869425","334847118736015367569779116448822692220","316933571236248473840169727934558035077"],"threshold":0.9},"id":"CVE-2025-62193-e6c98383","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}