CVE-2025-54923

Network-Exposed Service - Code Injection

Title source: llm

Description

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.

Scores

EPSS 0.0094
EPSS Percentile 76.1%

Classification

CWE
CWE-502
Status draft

Timeline

Published Aug 20, 2025
Tracked Since Feb 18, 2026