PT-2026-29565 · Unknown · Replicator

·

CVE-2026-2265

·

Published

2026-04-01

·

Updated

2026-04-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Replicator versions 1.0.5
Description A remote code execution (RCE) issue exists in applications utilizing the Replicator node package manager. The vulnerability stems from the deserialization of untrusted user input, leading to the execution of the resulting object. This allows for unauthenticated access and potential compromise of systems.
Recommendations Update Replicator to a version that addresses this issue.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2265
GHSA-2GMP-34J9-FQJM

Affected Products

Replicator