Description
All versions of cryo are vulnerable to code injection due to an Insecure implementation of deserialization.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.0.6
References
Related Issues
- [Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-code-completion - CVE-2026-46580
- [Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat - @theia/ai-claude-code - CVE-2026-46580
- Editor.js vulnerable to Code Injection - CVE-2022-23474
- TypeORM: migration:generate template-literal code injection - CVE-2026-73651
You might also like:
- Tags:
- npm
- cryo
Anything's wrong? Let us know Last updated on September 12, 2023


