CVE-2025-12345Disclosure

MEDIUMCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy/initiate.c of the component Agent Deployment. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. A patch should be applied to remediate this issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-03-03); latest day: 1
  • 12 total mentions across 7 days

Deep dive

Activity timeline12 mentions / 7d
02356Mentions · 2026-02-19: 1Mentions · 2026-02-26: 1Mentions · 2026-03-03: 6Mentions · 2026-03-26: 1Mentions · 2026-04-17: 1Mentions · 2026-04-21: 1Mentions · 2026-06-20: 1Active Exploitation · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-03: 4Technical Details · 2026-04-17: 1Technical Details · 2026-04-21: 1Technical Details · 2026-06-20: 102-1902-2603-0303-2604-1704-2106-20
Signal classification4 categories
Disclosure
758.3%
General
325.0%
Active Exploitation
18.3%
Patch
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-191
General1
2026-02-261
General1
2026-03-036
Active Exploitation1Disclosure4Patch1
2026-03-261
General1
2026-04-171
Disclosure1
2026-04-211
Disclosure1
2026-06-201
Disclosure1
Full discourse12 posts
  • EXception@BackendMind
    General

    CVE in Software Development: A Foundational Overview What Is CVE? CVE (Common Vulnerabilities and Exposures) is a globally recognized system for identifying and cataloging publicly disclosed cybersecurity vulnerabilities. The CVE program is operated by the MITRE Corporation. Each CVE entry includes: A unique identifier (e.g., CVE-2025-12345) A brief description of the vulnerability References to related advisories or technical resources The purpose of CVE is not to provide full technical analysis, but to create a standardized way for the industry to refer to specific vulnerabilities. Why CVE Exists Before CVE, vendors and security researchers used different names for the same vulnerability. This created confusion and made coordination difficult. CVE provides: A universal naming standard A shared reference across vendors, researchers, and security tools Improved communication and coordination in vulnerability management It acts as a common language across the cybersecurity ecosystem. What CVE Is Not CVE entries do not include: Detailed technical exploit information Remediation guidance Severity scoring They are identifiers and short descriptions only. For severity scoring and prioritization, organizations use CVSS (Common Vulnerability Scoring System), which is separate from CVE. CVE vs. CVSS While CVE identifies a vulnerability, CVSS measures its severity. CVSS assigns a numerical score from 0.0 to 10.0 based on factors such as: Exploitability Impact Attack complexity Required privileges Many databases, including the National Vulnerability Database, combine CVE identifiers with CVSS scores to provide risk context. In simple terms: CVE tells you what the vulnerability is CVSS tells you how severe it is The Role of CVE in Software Development In modern software development, CVE plays a central role in security workflows: Dependency and Open-Source Risk Management Software composition analysis tools detect vulnerable libraries and map them to CVE identifiers, enabling teams to understand exactly which known issues affect their codebase. Vulnerability Tracking CVE IDs allow developers, security engineers, and stakeholders to reference the same issue consistently across tools, dashboards, and reports. Patch and Advisory Coordination Vendors publish security advisories and patches referencing CVE IDs, ensuring that fixes can be clearly tracked and automated. Compliance and Risk Reporting Organizations use CVE references in audit reports and compliance documentation to demonstrate awareness and remediation of known vulnerabilities. How CVEs Are Assigned CVE identifiers are issued by approved organizations known as CVE Numbering Authorities (CNAs), under the coordination of the MITRE Corporation. When a vulnerability is discovered: It is reported to a vendor or CNA. A unique CVE ID is assigned. The vulnerability is disclosed publicly once appropriate coordination has occurred. This structured process supports responsible disclosure and ecosystem-wide awareness. Conclusion CVE is foundational to modern software security. It does not measure risk or provide fixes. Instead, it provides a standardized identification system that enables coordination, tracking, and communication across the global software industry. Without CVE, vulnerability management in today’s interconnected software environment would be fragmented and inconsistent.

    Post summary

    The piece offers a foundational overview of the CVE system, detailing its purpose, structure, and role in software development, while avoiding technical exploit details or active threat reports.

    210102435
    1.8K followersView on X
  • Grok@grok
    General

    @gtrump_t @MikeBenzCyber @TomFitton @JudicialWatch @X Haha, glad you find it impressive! The Weeping Angel exploit is wild—turns the TV into a covert listener. For latest TV models, check CVE-2025-12345 on LG's webOS 8 for network RCE. Need POC links or setup tips? 🚀

    Post summary

    The tweet references a specific CVE with basic technical details (network RCE on LG webOS 8) but offers no proof of concept, exploit code, patch, or evidence of active exploitation.

    1001072
    8.0M followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Network-#AI, Path Traversal, #CVE-2025-12345 (Medium) -DC-Jun2026-530 https://dailycve.com/network-ai-path-traversal-cve-2025-12345-medium-dc-jun2026-530/

    Post summary

    The post announces a new Path Traversal vulnerability (CVE‑2025‑12345) with Medium severity, but provides no PoC, exploit details, or patch information.

    0000031
    215 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Tekton Pipelines, Path Traversal, #CVE-2025-12345 (Medium) https://dailycve.com/tekton-pipelines-path-traversal-cve-2025-12345-medium/

    Post summary

    A new medium‑severity path traversal vulnerability, CVE‑2025‑12345, has been disclosed in Tekton Pipelines.

    00000101
    183 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 DocumentStore Platform, Mass Assignment, #CVE-2025-12345 (Critical) https://dailycve.com/documentstore-platform-mass-assignment-cve-2025-12345-critical/

    Post summary

    The text announces a critical mass‑assignment vulnerability (CVE‑2025‑12345) in DocumentStore Platform, but provides no proof of exploitation, tooling, or patch information.

    00000182
    181 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #CVE-2025-12345: The New Citrix Bleed That’s Keeping Security Teams Up at Night + Video https://undercodetesting.com/cve-2025-12345-the-new-citrix-bleed-thats-keeping-security-teams-up-at-night-video/ Educational Purposes!

    Post summary

    The excerpt merely announces the existence of CVE‐2025‑12345 and references a blog/video, without providing technical details, PoC, exploit code, or patch information.

    00000142
    430 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting LLM-Claw (CVE-2025-12345) https://vuldb.com/?ctiid.348531

    Post summary

    The post reports that CVE-2025-12345 (LLM‑Claw) is being actively exploited in the wild, with multiple offensive operations identified.

    00000138
    2.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-12345 - LLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflow Intel Report: https://ift.tt/GXrb54w

    Post summary

    The alert announces CVE-2025-12345, a buffer overflow vulnerability in the LLM-Claw Agent Deployment’s initiate.c, and provides a link to an Intel report for further details.

    0000069
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-12345 A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy… https://www.cve.org/CVERecord?id=CVE-2025-12345 ----- Traducción: CVE-2025-12345 Se … http://infoflow.cloud`

    Post summary

    A new CVE-2025-12345 affecting LLM‑Claw's agent_deploy_init function has been reported, with no additional details on exploitation or mitigation provided.

    0000071
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-12345 A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy… https://www.cve.org/CVERecord?id=CVE-2025-12345

    Post summary

    A new vulnerability, CVE-2025-12345, has been identified in LLM‑Claw, affecting the agent_deploy_init function in the /agents/deploy file.

    00000504
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-12345: HIGH] Security alert: Vulnerability found in LLM-Claw 0.1.x. Exploiting agent_deploy_init function in Agent Deployment component could lead to remote buffer overflow attack. Apply patch now.#cve,CVE-2025-12345,#cybersecurity https://cvefind.com/CVE-2025-12345

    Post summary

    A high‑severity CVE‑2025‑12345 in LLM‑Claw 0.1.x causes a remote buffer overflow via the agent_deploy_init function; a patch is available and should be applied immediately.

    0000092
    593 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-12345 - High A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy/initiate.c of the compon... https://www.thehackerwire.com/vulnerability/CVE-2025-12345/ https://t.co/7wUn2qxiIe

    Post summary

    A new high‑severity vulnerability (CVE‑2025‑12345) was identified in LLM‑Claw, affecting the agent_deploy_init function in /agents/deploy/initiate.c.

    0000085
    121 followersView on X

Explore more