PT-2025-39448 · Unknown · Lazyagi Lazyllm

0X1F

·

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10965

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LazyAGI LazyLLM versions prior to 0.6.2
Description A security issue has been identified in LazyAGI LazyLLM. This concerns the deserialization of data within the lazyllm call function located in the lazyllm/components/deploy/relay/server.py file. This manipulation can be initiated remotely. The details of the exploit have been publicly disclosed.
Recommendations Update to a version later than 0.6.1.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10965

Affected Products

Lazyagi Lazyllm