External risk intelligence

Pyfury Arbitrary Code Execution via Untrusted Data Deserialization

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-61622

The vulnerability exists in a serialization library (pyfury). Libraries are typically embedded components within applications rather than standalone internet-facing services. While the library may process data from public-facing endpoints, it is not inherently internet-facing by design in common deployments, and exposure depends entirely on how a developer integrates the library into their specific application architecture.

Deserialization

Apache Fory

0.1.0 to 0.10.30.12.0 to 0.12.2

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the pyfury library could allow unauthorized code execution if applications deserialize untrusted data. While the library itself is not directly internet-facing, its use in processing data from external sources presents a potential risk. The main concern is confirming if and how this library is used within our systems and if it handles data from untrusted origins.

  • Code execution risk from untrusted data.
  • Crucial for embedded library security oversight.
  • Confirm usage and data source relevance.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending specially crafted serialized data to an application that uses the vulnerable library. This data, when deserialized, tricks the application into using a less secure method that allows arbitrary code to be executed on the system.

  • Data from untrusted sources required.
  • Deserializing untrusted data triggers vulnerability.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

When an application deserializes untrusted data using pyfory or legacy pyfury, arbitrary code execution could occur. This risk is present when an application processes pyfury serialized data obtained from untrusted sources, allowing an attacker to potentially execute arbitrary code.

  • Application code that processes untrusted data.
  • Deserializing data from untrusted sources.
  • Arbitrary code execution on the system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The application owner or development team responsible for integrating the pyfury library is likely accountable for addressing this vulnerability. The first practical step is to identify all instances of the affected library within your codebase, determine which applications utilize it, and assess their business criticality and exposure. Once identified, coordinate with the relevant teams to plan remediation, prioritizing efforts based on risk.

  • Application owners should own remediation.
  • Verify applications using the library.
  • Plan updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the pyfury library?

Pyfury is a serialization library, which is software code used to convert complex objects into a format that can be easily stored or transmitted between systems. Apache Fory (pyfury) is primarily used within applications to handle data exchange. Because it acts as an embedded component rather than a standalone service, its functionality is entirely dependent on how it is integrated into the architecture of the host application.

What does deserialization of untrusted data mean for CVE-2025-61622?

This vulnerability, classified as CWE-502 (Deserialization of Untrusted Data), occurs when software reconstructs data from an untrusted source without sufficient validation. In this CVE, the library mistakenly allows a fallback to the 'pickle' module during this process. Because pickle can execute arbitrary code when loading data, an attacker providing malicious input can trick the application into running unauthorized commands on the underlying system.

How can an attacker trigger this vulnerability?

An attacker must successfully send a specially crafted, serialized data stream to an application that processes it using a vulnerable version of the library. Importantly, the flaw is only triggered when the application deserializes this specific, malicious payload. If an application uses the library but never processes serialized data from external or untrusted sources, it does not meet the necessary conditions for this specific code execution path.

Do I need to worry if my application is not internet-facing?

Halo Surface Signal notes that since this is an embedded library, it is not inherently internet-facing by design. However, risk depends on your specific architecture. Even if a service is internal, it remains relevant if it processes data from untrusted origins, such as user-provided uploads or data from less secure parts of your network. Assess whether your application's input sources could potentially carry crafted serialized data.

When should I update my pyfury library?

You should prioritize updating to version 0.12.3 or later as soon as possible. Because this library is embedded, you must first perform a code audit to identify every application using the affected versions. Once identified, coordinate with your development teams to apply the update, which removes the insecure pickle-fallback mechanism, effectively neutralizing the vulnerability.

References