References https://nvd.nist.gov/vuln/detail/CVE-2020-22083 https://zone.ci/aliyun/ali_nvd/105952.html https://github.com/jsonpickle/jsonpickle/issues/332 https://www.sentinelone.com/vulnerability-database/cve-2020-22083/ https://payatu.com/advisory/code-execution-json-pickle/ https://versprite.com/blog/application-security/into-the-jar-jsonpickle-exploitation/ https://sourcery.ai/vulnerabilities/python-jsonpickle-deserialization-rce https://github.com/pyupio/safety-db/issues/2368
Related VulnerabilitiesPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-58191: Appium base-driver <=10.6.0 - Reflected Cross-Site ScriptingPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadPoCpackage-json: NPM package.json DisclosurePoCCVE-2026-3395: MaxSite CMS <=109.1 - Remote Code ExecutionPoCvlife-fastjson-rce: Vlife FastJSON - Remote Code ExecutionPoCazure-functions-hostjson-exposure: Azure Functions host.json Configuration ExposurePoCCVE-2025-1302: JSONPath Plus < 10.3.0 - Remote Code Execution(CVE-2025-9910)jsondiffpatch 0.7.2前版本跨站脚本漏洞fastjson-rce-all: Fastjson Deserialization RCEhikvision-center-fastjson-rce: 海康威视综合安防-运行管理中心-Fastjson-远程命令执行漏洞