Active Job - Object injection security vulnerability
Moderate severity
GitHub Reviewed
Published
Jan 16, 2026
to the GitHub Advisory Database
•
Updated Jan 20, 2026
Description
Published to the GitHub Advisory Database
Jan 16, 2026
Reviewed
Jan 16, 2026
Last updated
Jan 20, 2026
Active Job vulnerability: An Active Job bug allowed String arguments to be deserialized as if they were Global IDs, an object injection security vulnerability.
References