
CVE-2026-25358 Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2. https://www.cve.org/CVERecord?id=CVE-2026-25358
Post summary
The text describes CVE‑2026‑25358 as a deserialization-based object injection flaw in Meloo affecting versions below 2.8.2, but provides no PoC, exploit code, or evidence of active exploitation.
