{"id":"CVE-2025-61385","aliases":["PYSEC-2026-1766"],"url":"https://o3.security/vulnerability/CVE-2025-61385","summary":"pg8000 SQL injection vulnerability via a specially crafted Python list input","details":"SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a specially crafted Python list input to function pg8000.native.literal.","published":"2025-10-27T18:31:13Z","modified":"2026-07-07T17:56:15.340375742Z","cvss":null,"epss":{"score":0.00336,"percentile":0.26039,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pg8000","fixedVersion":"1.31.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61385"},{"type":"PACKAGE","url":"https://codeberg.org/tlocke/pg8000"},{"type":"WEB","url":"https://codeberg.org/tlocke/pg8000/commit/8663c746b02286c32f19c385f0e2e5da9e4fa140"},{"type":"WEB","url":"https://github.com/bmcyver/vulnerability-research/tree/main/CVE-2025-61385"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:15.340375742Z"}}