CVE-2025-49597: Handcraftedinthealps Goodby-Csv
Low severity, CVSS 3.9. EPSS: 0.2% chance of exploitation in the next 30 days.
handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called "gadget chain" presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. The problem is patched with Version 1.4.3.
Affected products
- Handcraftedinthealps Goodby-Csv: before 1.4.3 (fixed in 1.4.3)
Published 2025-06-13. Last modified 2026-06-17.