Nuke.Tooling is vulnerable to Deserialization of Untrusted Data
45
Medium Risk
Affected versions of this package use BinaryFormatter, a library known to be vulnerable to deserialization of untrusted data. This flaw could potentially lead to Remote Code Execution (RCE) or Denial of Service (DoS) attacks.
You are affected if you are using a version which is within vulnerability ranges
Nuke.Tooling is vulnerable to Deserialization of Untrusted Data in versions 0.1 - 8.1.4.
Upgrade the Nuke.Tooling library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant