syncfusion-winforms-docking-manager
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/serialization.md
LOWAnomalyLOW
references/serialization.md
The fragment is consistent with product documentation and sample code for docking-layout persistence and contains no clear malicious behavior. SQL usage is parameterized. However, loading database-controlled bytes through BinaryFmtStream is a significant security concern if the underlying serializer uses BinaryFormatter or another unsafe polymorphic deserializer. Treat persisted layout data as untrusted, use a safe allowlisted format, authenticate and validate records, enforce size limits, and avoid unsafe binary deserialization. Assessment is limited to the supplied portion and cannot establish the implementation of AppStateSerializer.
Confidence: 90%Severity: 65%
Audit Metadata