Deserialization Vulnerability in SuiteCRM Affects User Data Security
CVE-2025-54785
What is CVE-2025-54785?
SuiteCRM, a widely-used open-source CRM application, has a deserialization vulnerability in versions 7.14.6 and 8.8.0 due to inadequate validation of user-supplied input before invoking the unserialize function. This oversight can lead to severe security implications, including unauthorized access to sensitive information, potential privilege escalations, service disruptions, and exploitation for cryptomining or ransomware attacks. Users and administrators are advised to upgrade to the patched versions 7.14.7 and 8.8.1 to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM >= 7.14.6, < 7.14.7 < 7.14.6, 7.14.7
SuiteCRM >= 8.8.0, < 8.8.1 < 8.8.0, 8.8.1
References
CVSS V3.1
Timeline
Vulnerability published
