PT-2026-26269 · Unknown · Themeton Finag

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2025-60237

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themeton Finag versions through 1.5.0
Description An issue exists in Themeton Finag where deserialization of untrusted data can lead to object injection. This allows for potential exploitation through the deserialization process.
Recommendations Update Finag to a version newer than 1.5.0.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-60237

Affected Products

Themeton Finag