CRITICALcrates.io

risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

CVE-2025-61588Published 11 months agoUpdated 5 days agoSource: OSV

Affected packages

  • risc0-aggregationbefore 0.9
  • risc0-zkos-v1compat
  • risc0-zkvm
  • risc0-zkvm-platform

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read` | HackTribune