Vendorsjsonpickle Projectjsonpickleall versions
Vulnerabilities

jsonpickle Project jsonpickle

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-22083
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data
Published 2020-12-17 · Modified
9.8EPSS 0.064