A vulnerability has been found in Dromara Sa-Token up to...
Low severity
Unreviewed
Published
Dec 30, 2025
to the GitHub Advisory Database
•
Updated Dec 30, 2025
Description
Published by the National Vulnerability Database
Dec 30, 2025
Published to the GitHub Advisory Database
Dec 30, 2025
Last updated
Dec 30, 2025
A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References