CVE-2025-2622: Aizuda Snail-Job
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the argument nodeExpression leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
- Aizuda Snail-Job: version 1.4.0 only
Published 2025-03-22. Last modified 2026-06-17.