An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
References
| Link | Resource |
|---|---|
| https://github.com/mtrojnar/osslsigncode/issues/475 | Not Applicable |
| https://github.com/mtrojnar/osslsigncode/pull/477 | Not Applicable |
| https://github.com/mtrojnar/osslsigncode/releases/tag/2.11 | Not Applicable |
| https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8 | Patch |
| https://github.com/ralphje/signify/issues/60 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-03-25 19:16
Updated : 2026-06-17 10:03
NVD link : CVE-2025-70887
Mitre link : CVE-2025-70887
CVE.ORG link : CVE-2025-70887
JSON object : View
Products Affected
ralphje
- signify
CWE
CWE-269
Improper Privilege Management
