CVE-2025-27607: Potential RCE via missing `msgspec-python313-pre` dependency
(updated )
Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-27607 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →