Deserialization of Untrusted Data vulnerability in...
Critical severity
Unreviewed
Published
Dec 18, 2025
to the GitHub Advisory Database
•
Updated Jan 20, 2026
Description
Published by the National Vulnerability Database
Dec 18, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Last updated
Jan 20, 2026
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
References