Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

rootio-python3.13: Unauthenticated Remote Code Execution Risk

ROOT-OS-DEBIAN-13-CVE-2025-13837
Summary

An attacker can run malicious code without being authorized. This affects all users of rootio-python3.13, which is used in some Root:Debian:13 systems. Update to the latest version to fix this issue.

What to do
  • Update rootio-python3.13 to version 3.13.5-2.root.io.14.
  • Update rootio-python3.13 to version 3.13.5-2.root.io.16.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:13 – rootio-python3.13 < 3.13.5-2.root.io.14
< 3.13.5-2.root.io.16
Fix: upgrade to 3.13.5-2.root.io.14
Original title
CVE-2025-13837 in rootio-python3.13 - Patched by Root
Original description
Root has patched CVE-2025-13837 in the rootio-python3.13 package for Root:Debian:13. Multiple fixed versions available.
Published: 17 Apr 2026 · Updated: 17 Apr 2026 · First seen: 30 Mar 2026