CVE detail
CVE-2020-22083 — CVE-2020-22083
Published 2020-12-17 · Modified 2026-06-17 · Vendor jsonpickle_project · Product jsonpickle · Source nvd
CRITICAL
severity
CVSS-derived band
0.0615
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References