{"id":"CVE-2018-1000210","details":"YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line \"currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);\" and blindly instantiates them. that can result in Code execution in the context of the running process. This attack appear to be exploitable via Victim must parse a specially-crafted YAML file. This vulnerability appears to have been fixed in 5.0.0.","aliases":["GHSA-rpch-cqj9-h65r"],"modified":"2026-07-08T14:58:31.789451Z","published":"2018-07-13T18:29:00.397Z","references":[{"type":"ADVISORY","url":"https://github.com/aaubry/YamlDotNet#version-500"},{"type":"ADVISORY","url":"https://github.com/aaubry/YamlDotNet/blob/f96b7cc40a0498f8bafdeb49df3aa23aa2c60993/YamlDotNet/Serialization/NodeTypeResolvers/TypeNameInTagNodeTypeResolver.cs#L35"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aaubry/yamldotnet","events":[{"introduced":"0"},{"last_affected":"8f20a18bb8a8c026bef7ce5ad66e7d8e198426df"}],"database_specific":{"cpe":"cpe:2.3:a:yamldotnet_project:yamldotnet:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.3.2"}],"source":"CPE_RANGE"}}],"versions":["v4.3.2","v4.3.1","v4.3.0","v4.2.4","v4.2.3","v4.2.2","v4.2.1","v4.2.0","v4.1.0","v4.0.0","v3.9.0","v3.8.0","v3.7.0","v3.6.1","v3.6.0","v3.3.1","v3.3.0","v3.2.2","v3.2.1","v3.2.0","v3.1.1","v3.1.0","v3.0.0","v2.3.0-rc","v2.2.0","v2.1.0","v2.0.1","v2.0.0","v1.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000210.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}