PT-2026-26269 · Unknown · Themeton Finag

CVE-2025-60237

·

Published

2026-03-19

·

Updated

2026-03-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Themeton Finag versions through 1.5.0
Description An issue exists in Themeton Finag where deserialization of untrusted data can lead to object injection. This allows for potential exploitation through the deserialization process.
Recommendations Update Finag to a version newer than 1.5.0.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60237

Affected Products

Themeton Finag