CVE-2025-61765 is a remote code execution vulnerability in python-socketio affecting versions prior to 5.14.0. In multi-server deployments that use a message queue backend such as Redis for inter-server communication, python-socketio encoded inter-server messages with Python's pickle module. When a Socket.IO server received a message from the queue, it treated the message as trusted and deserialized it using pickle.loads(). Because Python pickle deserialization is unsafe for untrusted input, an attacker who has already gained access to the message queue can submit a crafted pickle payload that triggers arbitrary code execution during deserialization, including through a malicious __reduce__ implementation. The issue is limited to deployments where the message queue used for internal server communications is compromised or otherwise writable by the attacker. Single-server deployments that do not use a message queue are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
pickle module for inter-server messaging and replace it with JSON encoding, eliminating the unsafe deserialization condition described in the advisory. In addition, review and harden the security of the message queue infrastructure used for inter-server communication, including access controls, authentication, network exposure, and credential management.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates and exploits a remote code execution (RCE) vulnerability (CVE-2025-61765) in python-socketio versions prior to 5.14.0, specifically in multi-server deployments using Redis as a message broker. The vulnerability arises from unsafe use of Python's pickle deserialization in the Socket.IO server's Redis manager, allowing an attacker with access to the Redis channel to execute arbitrary code on the server. The repository is structured as a complete test environment using Docker Compose, with the following main components: - **Redis server**: Acts as the message broker (not itself vulnerable). - **Vulnerable Socket.IO server** (`socketio_server/server.py`): A Flask-based server using a vulnerable version of python-socketio and Redis backend, exposing HTTP endpoints and automatically deserializing messages from Redis using pickle. - **Edge server** (`edge_server/app.py`): A Flask app that receives HTTP POST requests and publishes their contents to a Redis channel, simulating a client or another service in a multi-server setup. - **Exploit scripts** (`poc.py`, `socketio_server/poc.py`): Python scripts that generate malicious pickle payloads and deliver them either via HTTP to the edge server or directly to Redis. Payloads include arbitrary command execution, system information gathering, and installation of an SSH backdoor. Key endpoints include HTTP interfaces for the vulnerable server and edge server, as well as the Redis TCP endpoint. Exploitation results in evidence files being written to `/tmp/evidence/` on the target server, and in the case of the SSH backdoor, to the user's `authorized_keys` file. The exploit is operational and demonstrates real-world impact, but is not weaponized for mass exploitation.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.