CVE-2020-20136: Quantconnect Lean
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
Affected products
- Quantconnect Lean: from 2.3.0.0, up to and including 2.4.0.1
Published 2020-12-14. Last modified 2026-06-17.