TopVuln

High-risk vulnerability digests

CVE-2025-60237

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-03-19 09:16:16
Affected versions
Finag <= 1.5.0
Summary
This is a critical unauthenticated deserialization vulnerability in Themeton Finag that enables object injection. All versions of Finag up to and including 1.5.0 are affected by this flaw. It has a 9.8 CVSS v3 score, placing it in the highest severity category.
Remediation
Update to the latest patched version of Themeton Finag as soon as a security fix is available. Block public access to vulnerable Finag instances until remediation is completed. Regularly scan systems for signs of unauthorized activity related to this vulnerability.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.