CVE-2025-61514

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Published 2025-10-16. Last modified 2026-06-17.