Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2018-3730 Vulnerability in npm package mcstatic
CVE-2017-16133 Vulnerability in npm package goserv
CVE-2020-7751 Vulnerability in npm package pathval
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-core
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore