PT-2026-27920 · Rascals · Rascals Pendulum

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25359

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rascals Pendulum versions prior to 3.1.5
Description An issue exists in rascals Pendulum that allows for Object Injection due to deserialization of untrusted data. This impacts the Pendulum software.
Recommendations Update to a version of rascals Pendulum that is version 3.1.5 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25359

Affected Products

Rascals Pendulum