PT-2025-53923 · Aizuda · Snail-Job
Icqv61
·
Published
2025-12-30
·
Updated
2025-12-30
·
CVE-2025-15246
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aizuda snail-job versions up to 1.7.0
Description
A flaw exists in the FurySerializer.deserialize function within the API component of aizuda snail-job. This issue involves the deserialization of the
argsStr argument, potentially allowing for remote exploitation. The details of the exploit have been publicly disclosed.Recommendations
Versions prior to 1.7.0 should be updated.
Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snail-Job