Insecure Deserialization: How a Serialized Blob Becomes Remote Code Execution
When an application rebuilds objects from untrusted serialized data, attacker-crafted gadget chains can run code during deserialization itself. Here is how object injection leads to RCE, and why data-only formats are the fix.