Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2020-8134 Vulnerability in npm package ghost
CVE-2022-39387 Vulnerability in maven package org.xwiki.contrib.oidc:oidc-authenticator
CVE-2022-1440 Vulnerability in npm package git-interface
CVE-2021-3461 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-28480 Vulnerability in maven package org.webjars.npm:jointjs