replicator vulnerable to Deserialization of Untrusted Data
Critical severity
GitHub Reviewed
Published
Dec 15, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Dec 15, 2022
Published to the GitHub Advisory Database
Dec 15, 2022
Reviewed
Dec 15, 2022
Last updated
Jan 29, 2023
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
References