Deserialization Vulnerability in SewKinect by Giantspatula
CVE-2025-10974
Key Information:
- Vendor
Giantspatula
- Status
- Vendor
- CVE Published:
- 25 September 2025
Badges
What is CVE-2025-10974?
The SewKinect product by Giantspatula contains a deserialization vulnerability within its Endpoint functionality. This flaw is found in the pickle.loads function located in the /calculate file. An attacker can manipulate input parameters, specifically body_parts or point_cloud, to execute malicious payloads remotely. With this vulnerability disclosed to the public, it necessitates immediate attention and a review of security measures to protect affected systems.
Affected Version(s)
SewKinect 7fd963ceb3385af3706af02b8a128a13399dffb1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved