Skip to content

Comments

[GHSA-hf23-9pf7-388p] Deserialization of Untrusted Data and Code Injection in xstream#7030

Open
levpachmanov wants to merge 1 commit intolevpachmanov/advisory-improvement-7030from
levpachmanov-GHSA-hf23-9pf7-388p
Open

[GHSA-hf23-9pf7-388p] Deserialization of Untrusted Data and Code Injection in xstream#7030
levpachmanov wants to merge 1 commit intolevpachmanov/advisory-improvement-7030from
levpachmanov-GHSA-hf23-9pf7-388p

Conversation

@levpachmanov
Copy link

Updates

  • Affected products

Comments
The problematic code was introduced only in 1.4.10 - x-stream/xstream@f38a1da

@github-actions github-actions bot changed the base branch from main to levpachmanov/advisory-improvement-7030 February 23, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant