Inclusion of Functionality from Untrusted Control Sphere in python-json-logger - CVE-2025-27607
Published: July 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). A remote attacker can trick the victim into opening a specially crafted data, trigger the vulnerability and execute arbitrary code on the target system.
Affected software
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cognos Analytics
How to mitigate CVE-2025-27607
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP6, 12.0.4 FP1, 12.1.0 IF2