Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2021-4264 Vulnerability in npm package dustjs-linkedin
CVE-2014-0168 Vulnerability in maven package org.jolokia:jolokia-core
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2020-14967 Vulnerability in maven package org.webjars.bower:jsrsasign
CVE-2021-21346 Vulnerability in maven package com.thoughtworks.xstream:xstream