{"id":"CVE-2025-66631","aliases":["GHSA-wq34-7f4g-953v"],"url":"https://o3.security/vulnerability/CVE-2025-66631","summary":"CSLA .NET is vulnerable to Remote Code Execution via WcfProxy","details":"CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability is fixed in version 6.0.0. To workaround this issue, remove the WcfProxy in data portal configurations.","published":"2025-12-09T03:18:37.698Z","modified":"2026-07-15T01:49:06.120365694Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Csla","fixedVersion":"6.0.0"}],"fix":{"url":"https://github.com/MarimerLLC/csla/pull/4018","label":"MarimerLLC/csla#4018"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66631.json"},{"type":"ADVISORY","url":"https://github.com/MarimerLLC/csla/security/advisories/GHSA-wq34-7f4g-953v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66631"},{"type":"REPORT","url":"https://github.com/MarimerLLC/csla/issues/4001"},{"type":"FIX","url":"https://github.com/MarimerLLC/csla/pull/4018"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.120365694Z"}}