Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2020-16022 Vulnerability in npm package electron
CVE-2023-32200 Vulnerability in maven package org.apache.jena:jena
CVE-2021-43466 Vulnerability in maven package org.thymeleaf:thymeleaf-spring5
CVE-2020-28272 Vulnerability in npm package keyget
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js