logo

Discovering a Deserialization Vulnerability in LINQPad

ID: 1a1f7b87-f21d-5c35-b8e5-cb23493d2284

STIX ID: report--1a1f7b87-f21d-5c35-b8e5-cb23493d2284

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

A researcher found a deserialization vulnerability in LINQPad Pro (v5.48.00) where BinaryFormatter.Deserialize processes a writable per-user cache file, enabling RCE via a crafted ysoserial payload; the issue was responsibly disclosed and patched in LINQPad 5.52.01 (CVE-2024-53326).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.