PT-2026-27921 · Rascals · Rascals Vex

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25360

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rascals Vex versions prior to 1.2.9
Description An issue exists in rascals Vex that allows for object injection due to deserialization of untrusted data. This impacts the Vex component.
Recommendations Update rascals Vex to version 1.2.9 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25360

Affected Products

Rascals Vex