VYPR
Critical severity9.6GHSA Advisory· Published Oct 27, 2025· Updated Apr 15, 2026

CVE-2025-61385

CVE-2025-61385

Description

SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a specially crafted Python list input to function pg8000.native.literal.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pg8000PyPI
< 1.31.51.31.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.