A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
{ "github_reviewed": true, "cwe_ids": [ "CWE-502" ], "severity": "CRITICAL", "github_reviewed_at": "2022-12-15T23:31:51Z", "nvd_published_at": "2022-12-15T19:15:00Z" }