MEDIUM
Replicator 1.0.5 is vulnerable to Remote Code Execution through Insecure Deserialization
Published Apr 1, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.37%
Description
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute the resulting object.
Affected products
-
- Version 1.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Replicator | Replicator | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
replicator
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | replicator | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-17958 Advisory
- https://github.com/advisories/GHSA-2gmp-34j9-fqjm Advisory
- https://github.com/inikulin/replicator
- https://github.com/inikulin/replicator/pull/19
- https://morielharush.github.io/2026/03/31/cve-2026-2265-replicator-deserialization-of-untrusted-data
- https://nvd.nist.gov/vuln/detail/CVE-2026-2265
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Apr 1, 2026
Updated Apr 1, 2026
Reserved Feb 9, 2026
Link CVE-2026-2265
CISA Vulnrichment
Updated Apr 1, 2026
ENISA EUVD
EUVD-2026-17958 GHSA-2GMP-34J9-FQJM Assigner certcc
Published Apr 1, 2026
Updated Apr 1, 2026
Exploited since n/a
Link EUVD-2026-17958