Deserialization Vulnerability in LoftOcean TinySalt Plugin
CVE-2025-49455
9.8CRITICAL
What is CVE-2025-49455?
The LoftOcean TinySalt plugin contains a deserialization vulnerability that permits object injection. This issue arises from the improper handling of untrusted data, allowing attackers to manipulate serialized data and execute arbitrary code. Updates are essential for users running versions prior to 3.10.0 to mitigate potential risks associated with this vulnerability.
Affected Version(s)
TinySalt < 3.10.0