CVE-2025-14606 | tiny-rdm Tiny RDM up to 1.2.5 Pickle Decoding pickle_convert.go pickle.loads deserialization (EUVD-2025-203263)
A vulnerability, which was classified as critical, has been found in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the function pickle.loads of the file pickle_convert.go of the component Pickle Decoding. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2025-14606. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.