CVE-2018-6331: Facebook Buck
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.
Affected products
- Facebook Buck: before 2018.06.25.01 (fixed in 2018.06.25.01)
Published 2018-12-31. Last modified 2026-06-17.