THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w23p-wrp7-ch38 (critical) — Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)

[GHSA] GHSA-w23p-wrp7-ch38 (critical) — Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)

medgithub_advisoriesPublished 2026-08-28

GHSA-w23p-wrp7-ch38 Severity: critical CVE: CVE-2026-55220

Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)

## Summary

`Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource()` deserializes the `*__hotspots` object-store column through the `Pimcore\Tool\Serialize::unserialize()` wrap

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w23p-wrp7-ch38