CVE 5.3 MEDIUM

aizuda snail-job API FurySerializer.deserialize deserialization_CVE-2025-15246

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

Basic Information

ID CVE-2025-15246
Source VulDB
Published Dec 30, 2025 at 11:32

Affected Product

Vendor aizuda
Product snail-job
Version 1.0
Affected Versions aizuda snail-job 1.0
aizuda snail-job 1.1
aizuda snail-job 1.2
aizuda snail-job 1.3
aizuda snail-job 1.4
aizuda snail-job 1.5
aizuda snail-job 1.6
aizuda snail-job 1.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.