Insecure Deserialization in ERC Affected by JSONpickle
CVE-2025-55136

5.7MEDIUM

Key Information:

Vendor

Tae898

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-55136?

The Emotion Recognition in Conversation (ERC) application, specifically version 0.3, is susceptible to insecure deserialization due to its reliance on JSONpickle for object serialization. This vulnerability could allow an attacker to execute arbitrary code during the deserialization process, potentially leading to unauthorized access or manipulation of application data. Developers are encouraged to review the usage of JSONpickle and implement proper validation and sanitization measures to mitigate this risk.

Affected Version(s)

ERC 0 <= 0.3

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55136 : Insecure Deserialization in ERC Affected by JSONpickle