THREAT OPS › Threat News › [GHSA] GHSA-w23p-wrp7-ch38 (critical) — Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
[GHSA] GHSA-w23p-wrp7-ch38 (critical) — Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
GHSA-w23p-wrp7-ch38 Severity: critical CVE: CVE-2026-55220
Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
## Summary
`Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource()` deserializes the `*__hotspots` object-store column through the `Pimcore\Tool\Serialize::unserialize()` wrap
Indicators of compromise
- CVE-2026-55220cve
Original source: https://github.com/advisories/GHSA-w23p-wrp7-ch38