Insecure Deserialization in ERC Affected by JSONpickle
CVE-2025-55136
5.7MEDIUM
What is CVE-2025-55136?
The Emotion Recognition in Conversation (ERC) application, specifically version 0.3, is susceptible to insecure deserialization due to its reliance on JSONpickle for object serialization. This vulnerability could allow an attacker to execute arbitrary code during the deserialization process, potentially leading to unauthorized access or manipulation of application data. Developers are encouraged to review the usage of JSONpickle and implement proper validation and sanitization measures to mitigate this risk.
Affected Version(s)
ERC 0 <= 0.3