CVE-2024-28212: Naver Ngrinder

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Affected products

  • Naver Ngrinder: before 3.5.9 (fixed in 3.5.9)

Published 2024-03-07. Last modified 2026-06-17.