| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| CompositeC1.Core |
| nuget |
| < 6.13 |
| 6.13 |
The vulnerability stems from Json.NET deserialization with TypeNameHandling enabled (Auto/Objects) combined with an insufficient type binder. Key issues:
KEV Misses 88% of Exploited CVEs- Get the report