{"id":"GHSA-f5cx-h789-j959","summary":"PowSyBl Core allows deserialization of untrusted SparseMatrix data","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nThis is a disclosure for a security vulnerability in the `SparseMatrix` class. The vulnerability is a deserialization issue that\ncan lead to a wide range of privilege escalations depending on the circumstances. The problematic area is the `read` method\nof the `SparseMatrix` class.\nThis method takes in an `InputStream` and returns a `SparseMatrix` object. We consider this to be a method that can be\nexposed to untrusted input in at least two use cases:\n- A user can adopt this method in an application where users can submit an `InputStream` and the application parses it into\na `SparseMatrix`. This can be a multi-tenant application that hosts many different users perhaps with different privilege\nlevels.\n- A user adopts the method for a local tool but receives the `InputStream` from external sources.\n\n#### Am I impacted?\nYou are vulnerable if you import non-controlled serialized `SparseMatrix` objects.\n\n\n### Patches\ncom.powsybl:powsybl-math:6.7.2 and higher\n\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nDo not use `SparseMatrix` deserialization (`SparseMatrix.read(...)` methods).\n\n### References\n[powsybl-core v6.7.2](https://github.com/powsybl/powsybl-core/releases/tag/v6.7.2)","aliases":["CVE-2025-47771"],"modified":"2025-06-20T16:25:12.264474Z","published":"2025-06-19T16:19:16Z","database_specific":{"github_reviewed_at":"2025-06-19T16:19:16Z","nvd_published_at":"2025-06-20T00:15:29Z","cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/powsybl/powsybl-core/security/advisories/GHSA-f5cx-h789-j959"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47771"},{"type":"WEB","url":"https://github.com/powsybl/powsybl-core/commit/8ed16ce41683c4aef5f6aa1dd5ae8642aa5ed2bd"},{"type":"PACKAGE","url":"https://github.com/powsybl/powsybl-core"},{"type":"WEB","url":"https://github.com/powsybl/powsybl-core/releases/tag/v6.7.2"}],"affected":[{"package":{"name":"com.powsybl:powsybl-math","ecosystem":"Maven","purl":"pkg:maven/com.powsybl/powsybl-math"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"fixed":"6.7.2"}]}],"versions":["6.3.0","6.3.1","6.3.2","6.4.0","6.4.0-RC2","6.4.1","6.5.0","6.5.0-RC1","6.5.1","6.6.0","6.6.0-RC1","6.6.1","6.7.0","6.7.0-RC1","6.7.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.7.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-f5cx-h789-j959/GHSA-f5cx-h789-j959.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}