CVE-2026-2265
Replicator 1.0.5 is vulnerable to Remote Code Execution through Insecure Deserialization
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Replicator · ReplicatorWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →