Jsonpickle Project maintains a Python serialization library designed to convert Python objects to and from JSON; the recurring exposure centers on deserialization of untrusted data, a structural risk inherent to any serialization mechanism that reconstructs objects from external input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jsonpickle Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-22083CRITICAL jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected an | Dec 17, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jsonpickle Project.
Media articles that mention a CVE ID that affects a product developed by Jsonpickle Project — matched by CVE ID, not by vendor name.