CVE-2025-70887

Published: Mar 25, 2026 Last Modified: Mar 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

https://github.com/mtrojnar/osslsigncode/issues/475
https://github.com/mtrojnar/osslsigncode/pull/477
https://github.com/mtrojnar/osslsigncode/releases/tag/2.11
https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4ad…
https://github.com/ralphje/signify/issues/60