Remote Code Execution Vulnerability in PyVista Product by PyVista
CVE-2025-61774

9.3CRITICAL

Key Information:

Vendor

Pyvista

Status
Vendor
CVE Published:
6 October 2025

What is CVE-2025-61774?

The PyVista product, which offers 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK), has a significant vulnerability in version 0.46.3. This issue arises from the improper use of the --extra-index-url option in pip, which allows local developers to inadvertently fetch and execute malicious code from packages not originally intended for PyPI. If an attacker publishes a package with a higher version number on PyPI than the original, the malicious code could be executed in the context of the user's application, thus exposing systems to critical supply chain attacks. As of now, a patched version addressing this vulnerability is not yet available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

pyvista = 0.46.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.