syncfusion-winforms-docking-manager

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/serialization.md

The fragment is consistent with product documentation and sample code for docking-layout persistence and contains no clear malicious behavior. SQL usage is parameterized. However, loading database-controlled bytes through BinaryFmtStream is a significant security concern if the underlying serializer uses BinaryFormatter or another unsafe polymorphic deserializer. Treat persisted layout data as untrusted, use a safe allowlisted format, authenticate and validate records, enforce size limits, and avoid unsafe binary deserialization. Assessment is limited to the supplied portion and cannot establish the implementation of AppStateSerializer.

Confidence: 90%Severity: 65%
Audit Metadata
Analyzed At
Sep 17, 2026, 08:06 AM
Package URL
pkg:socket/skills-sh/syncfusion%2Fwinforms-ui-components-skills%2Fsyncfusion-winforms-docking-manager%2F@702c72e7a4315b94ab535e1373754c9f2090040c68d9d33e40b1cb074a317dd0
Security Audit — socket — syncfusion-winforms-docking-manager