CVE-2025-60889

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
28/04/2026
Last modified:
18/05/2026

Description

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stellar-group:hpx:*:*:*:*:*:*:*:* 1.11.0 (including)