CVE-2025-14542
Unknown
Unknown - Not Provided
Remote Manual Endpoint Manipulation Enables Client-Side Exploitation
Publication date: 2025-12-13
Last updated on: 2025-12-13
Assigner: JFrog
Description
Description
The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can later change the manual to exploit the client.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jfrog | python-utcp | 1.0.4 |
| jfrog | python-utcp | 1.1.0 |
| jfrog | python-utcp | 1.0.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-501 | The product mixes trusted and untrusted data in the same data structure or structured message. |