{"id":"CVE-2019-10069","details":"In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.","modified":"2026-07-08T16:07:31.769490Z","published":"2019-05-31T22:29:01.160Z","references":[{"type":"ADVISORY","url":"https://github.com/godotengine/godot/pull/27398"},{"type":"ADVISORY","url":"https://godotengine.org/news"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/godotengine/godot","events":[{"introduced":"0"},{"fixed":"c5e2c83dcd6f3e1be295149c2b2e3d048dbab4c5"},{"introduced":"3e2247ca5301ffe7a45dbda473336636540b8fa8"},{"last_affected":"320f49f204cfbf9b480fe62aaa7718afb74920a5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.1"},{"introduced":"2.1.1"},{"last_affected":"3.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:godotengine:godot:*:*:*:*:*:*:*:*"}}],"versions":["3.1-stable","3.0-stable","2.0-stable","2.0-rc1","2.0-beta","1.1-rc3","1.1-rc2","1.1-rc1","1.0-rc2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10069.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}