
CVE-2026-25360 Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9. https://www.cve.org/CVERecord?id=CVE-2026-25360
Post summary
The text discloses a deserialization-based object injection vulnerability (CVE-2026-25360) affecting Vex versions up to 1.2.9, without providing PoC, exploit code, active exploitation evidence, or patch information.
