Sceawere

Vulnerability Detail

CVE-2026-93943UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Convex Object Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
2h ago
Vendor
ThemeREX Group
Product
Convex
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T08:17:06.803Z",
  "pubdate": "2026-10-10T08:17:06.803Z",
  "executiveSummary": "This vulnerability is classified as an Object Injection issue, stemming from the insecure deserialization of untrusted data within the Convex product by ThemeREX Group.\nThe flaw affects Convex versions from n/a through 1.16.0.\nBy manipulating serialized objects passed to the application, an unauthenticated or authenticated attacker can inject malicious objects into the application context.\nThis vulnerability poses a critical risk to the integrity and security of the affected system.\nSuccessful exploitation allows attackers to manipulate application logic, potentially leading to arbitrary code execution, unauthorized data access, or denial of service.\nThe vulnerability is inherent to how the application handles input data during the deserialization process, requiring no specialized access beyond the ability to supply crafted input to the vulnerable endpoint.",
  "technicalDetails": "The vulnerability originates from the improper handling of untrusted data during deserialization processes within the Convex application codebase.\nObject injection occurs when user-supplied, serialized data is deserialized by the application without sufficient validation or integrity checks.\nIn PHP and similar environments often used by such applications, deserialization mechanisms can instantiate arbitrary objects if the class definitions are available within the application's scope.\nAn attacker can craft a malicious serialized payload containing serialized objects of classes present in the application's environment. When the application deserializes this data, it reconstructs these objects, potentially triggering unintended code paths, such as magic methods (e.g., __destruct, __wakeup, __toString).\nThese magic methods can be leveraged to execute arbitrary code, modify application state, or facilitate further exploitation primitives, such as reading sensitive files or performing server-side request forgery (SSRF).\nThe attack flow involves: 1) Identification of an input vector that accepts serialized data; 2) Crafting a payload using available gadget chains—existing classes within the application that, when instantiated or destroyed, perform unintended actions; 3) Injecting the payload into the vulnerable application input vector; 4) Triggering the deserialization process, which results in the execution of the crafted gadget chain.\nThe lack of integrity verification for serialized data allows the attacker to influence the application flow entirely based on the available gadget repertoire within the application and its dependencies.\nAffected versions range from the initial release through 1.16.0.\nThe impact includes full compromise of the application context, potentially extending to the underlying server environment, depending on the permissions of the application process.\nThe technical root cause is the reliance on insecure deserialization functions—such as unserialize() in PHP—on untrusted input without implementing necessary defensive measures like object whitelisting or cryptographically signing serialized data."
}
CVE-2026-93943: Convex Object Injection Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere