Description

The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can later change the manual to exploit the client.

INFO

Published Date :

2025-12-13T09:59:41.376Z

Last Modified :

2025-12-13T22:54:11.290Z

Source :

JFROG
AFFECTED PRODUCTS

The following products are affected by CVE-2025-14542 vulnerability.

Vendors Products
Utcp
  • Utcp

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact