UBUNTU-CVE-2025-61774

Source
https://ubuntu.com/security/CVE-2025-61774
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61774.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-61774
Upstream
Published
2025-10-06T23:15:00Z
Modified
2026-05-20T16:23:39Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use--extra-index-url. But when --extra-index-url is used, pip always checks for the PyPI index first, and then the external index. One package listed in the code is not published in PyPI. If an attacker publishes a package with higher version in PyPI, the malicious code from the attacker controlled package may be pulled, leading to remote code execution and a supply chain attack. As of time of publication, a patched version is unavailable.

References

Affected packages

Ubuntu:25.10 / python-pyvista

Package

Name
python-pyvista
Purl
pkg:deb/ubuntu/python-pyvista?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.44.1-11

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-pyvista",
            "binary_version": "0.44.1-11"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61774.json"

Ubuntu:26.04:LTS / python-pyvista

Package

Name
python-pyvista
Purl
pkg:deb/ubuntu/python-pyvista?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.44.1-11
0.46.4-3ubuntu1
0.46.4-3ubuntu2
0.46.4-4ubuntu1
0.46.5-3
0.46.5-8
0.46.5-8ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-pyvista",
            "binary_version": "0.46.5-8ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61774.json"