HotspotImage deserialization RCE fix via allowed_classes whitelist (GHSA-w23p-wmp7-c438)
Security Advisory
GHSA-w23p-wmp7-c438
High
Pimcore
Affected:
- Pimcore <= 12.3.10
Referenced CVEs:
CVE-2026-55220 · 9.3
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.