Snipe-IT before 8.1.18 allows unsafe deserialization.
{ "github_reviewed": true, "severity": "MODERATE", "cwe_ids": [ "CWE-502" ], "nvd_published_at": "2025-09-19T03:15:47Z", "github_reviewed_at": "2025-09-19T17:14:39Z" }