PT-2026-26268 · Unknown · Themeton Zuut

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2025-60233

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themeton Zuut versions through 1.4.2
Description The software contains a flaw due to deserialization of untrusted data, which can lead to object injection. This allows for potential remote code execution. The vulnerability exists in the way the software handles serialized data, potentially allowing an attacker to inject malicious objects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-60233

Affected Products

Themeton Zuut