Skip to main content

CVE-2025-10965: Deserialization in LazyAGI LazyLLM

Medium
VulnerabilityCVE-2025-10965cvecve-2025-10965
Published: Thu Sep 25 2025 (09/25/2025, 20:02:07 UTC)
Source: CVE Database V5
Vendor/Project: LazyAGI
Product: LazyLLM

Description

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/components/deploy/relay/server.py. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

Technical Details

Data Version
5.1
Assigner Short Name
VulDB
Date Reserved
2025-09-25T10:11:23.733Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68d5da069e21be37e937d04c

Added to database: 9/26/2025, 12:10:46 AM

Last updated: 9/26/2025, 12:10:46 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats