lazyllm@0.4.1 vulnerabilities

A Low-code Development Tool For Building Multi-agent LLMs Applications.

Direct Vulnerabilities

Known vulnerabilities in the lazyllm package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Deserialization of Untrusted Data

lazyllm is an A Low-code Development Tool For Building Multi-agent LLMs Applications.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the lazyllm_call function in server.py. An attacker can execute arbitrary code or manipulate application behavior by sending specially crafted serialized data to the affected function.

How to fix Deserialization of Untrusted Data?

There is no fixed version for lazyllm.

[0,)