PT-2026-29565 · Unknown · Replicator

Moriel Harush

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-2265

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Replicator versions 1.0.5
Description A remote code execution (RCE) issue exists in applications utilizing the Replicator node package manager. The vulnerability stems from the deserialization of untrusted user input, leading to the execution of the resulting object. This allows for unauthenticated access and potential compromise of systems.
Recommendations Update Replicator to a version that addresses this issue.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-2265
GHSA-2GMP-34J9-FQJM

Affected Products

Replicator