lazyllm@0.2.2 vulnerabilities

A Low-code Development Tool For Building Multi-agent LLMs Applications.

Direct Vulnerabilities

Known vulnerabilities in the lazyllm package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Deserialization of Untrusted Data

lazyllm is an A Low-code Development Tool For Building Multi-agent LLMs Applications.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the lazyllm_call function in server.py. An attacker can execute arbitrary code or manipulate application behavior by sending specially crafted serialized data to the affected function.

Note: This capability is only accessible to developers and not to users, so no action will be taken to fix the issue.

How to fix Deserialization of Untrusted Data?

There is no fixed version for lazyllm.

[0,)