AttackFlow Findings Dictionary

Lack Of Serializable Annotation

Classes will not be serialized at runtime despite of the intention of making serializable



Fix Cost


Trust Level


If a class needs custom serialization methods (for example, requiring own binary serialization mechanism), it should implement ISerializable interface.

However, only implementing this interface doesn’t make a class serializable. The class should also hold a [Serializable] attribute.

public class RemoteMessage : ISerializable

// custom serialize methods

