CVE-2025-61774
Linux Debian vulnerability analysis and mitigation

Overview

PyVista version 0.46.3 is vulnerable to remote code execution (CVE-2025-61774) through dependency confusion. The vulnerability was discovered and disclosed on October 6, 2025. PyVista, which provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK), is affected when using specific package installation configurations (GitHub Advisory).

Technical details

The vulnerability stems from the use of the '--extra-index-url' parameter in pip installation commands. When this parameter is used, pip checks the PyPI index first before checking external indexes. Since the package 'vtk-osmesa' is not published on PyPI, an attacker could publish a malicious version of the package on PyPI with a higher version number, which would be installed instead of the legitimate package from the intended external source. The vulnerability has been assigned a CVSS v4.0 score of 9.3 CRITICAL with vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N (NVD).

Impact

The vulnerability can lead to remote code execution and supply chain attacks. If exploited, an attacker could execute malicious code by publishing a higher version of the package on PyPI, leading to the execution of attacker-controlled code during package installation (GitHub Advisory).

Mitigation and workarounds

As of the time of publication, no patched version is available. Users should exercise caution when using '--extra-index-url' in pip installations and consider implementing additional security measures to verify package sources (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22776HIGH8.7
  • Linux DebianLinux Debian
  • cpp-httplib
NoNoJan 12, 2026
CVE-2026-22801MEDIUM6.8
  • OpenJDK JDKOpenJDK JDK
  • java-21-openjdk-demo-fastdebug
NoYesJan 12, 2026
CVE-2026-22695MEDIUM6.1
  • OpenJDK JDKOpenJDK JDK
  • java-25-openjdk-static-libs
NoYesJan 12, 2026
CVE-2026-22251MEDIUM5.3
  • PythonPython
  • wlc
NoYesJan 12, 2026
CVE-2026-0665N/AN/A
  • Linux DebianLinux Debian
  • qemu
NoNoJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management