PT-2025-51115 · Tiny Rdm · Tiny Rdm
Zznq
·
Published
2025-12-13
·
Updated
2025-12-13
·
Zznq
·
Published
2025-12-13
·
Updated
2025-12-13
·
5.0
Medium
| Base vector | Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
pickle.loads function within the pickle convert.go file is affected. This can be triggered remotely and requires a high level of complexity to exploit, though exploitation appears difficult. The details of the issue have been publicly disclosed. The project maintainers were notified but have not yet responded.Exploit
Fix
Deserialization of Untrusted Data
RCE