PT-2019-11416 · Godot Engine+1 · Godot+1

Faless

·

Published

2019-05-31

·

Updated

2025-05-06

·

CVE-2019-10069

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Godot versions prior to 3.2
Description: The issue allows for remote code execution due to the deserialization policy not being applied correctly.
Recommendations: For Godot versions prior to 3.2, update to version 3.2 or later to resolve the issue.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5969
ALT-PU-2025-6296
CVE-2019-10069

Affected Products

Alt Linux
Godot