CVE-2025-11739

Product Version - Deserialization

Title source: llm

Description

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

Scores

EPSS 0.0007
EPSS Percentile 20.1%

Classification

CWE
CWE-502
Status draft

Timeline

Published Mar 10, 2026
Tracked Since Mar 11, 2026