---
id: CVE-2025-15246
title: A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS
summary: >-
  A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS.
  Affected by this vulnerability is the function FurySerializer.deserialize of
  the component API. This manipulation of the argument argsStr causes
  deserialization. Re…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-20
  - CWE-502
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15246'
references:
  - url: 'https://gitee.com/aizuda/snail-job/'
    label: cna@vuldb.com
  - url: 'https://gitee.com/aizuda/snail-job/issues/ICQV61'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338636'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338636'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00288
epssPercentile: 0.19198
ingestedAt: '2026-10-01T08:40:11.719Z'
---

## Overview

A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
