CVE-2025-49507: Loftocean Cozystay

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through < 1.7.1.

Affected products

  • Loftocean Cozystay: up to and including 1.7.1

Published 2025-06-10. Last modified 2026-06-17.