« Volver al listado

CVE-2025-14660

Estado: AplazadaBaja (2.9)—

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access controls. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been published and may be used. Upgrading to version 1.0.0-alpha.32 addresses this issue. Patch name: 5f7315e05852faf3a9c177c0a34f9ea9b0371d3d. It is recommended to upgrade the affected component.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-14660",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-14660",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-15T20:54:55.484541Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.2
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 2.9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "PROOF_OF_CONCEPT",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@vuldb.com",
      "affectedData": [
        {
          "vendor": "DecoCMS",
          "modules": [
            "Workspace Domain Handler"
          ],
          "product": "Mesh",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0-alpha.0"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.1"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.2"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.3"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.4"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.5"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.6"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.7"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.8"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.9"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.10"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.11"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.12"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.13"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.14"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.15"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.16"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.17"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.18"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.19"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.20"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.21"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.22"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.23"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.24"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.25"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.26"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.27"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.28"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.29"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.30"
            },
            {
              "status": "affected",
              "version": "1.0.0-alpha.31"
            },
            {
              "status": "unaffected",
              "version": "1.0.0-alpha.32"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-14T13:15:35.963",
  "references": [
    {
      "url": "https://github.com/decocms/mesh/commit/5f7315e05852faf3a9c177c0a34f9ea9b0371d3d",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/decocms/mesh/pull/1967",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/decocms/mesh/pull/1967#issue-3700934099",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/decocms/mesh/pull/1967#issuecomment-3622379237",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://github.com/decocms/mesh/releases/tag/runtime-v1.0.0-alpha.32",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?ctiid.336392",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?id.336392",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?submit.713741",
      "source": "cna@vuldb.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@vuldb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-266"
        },
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access controls. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been published and may be used. Upgrading to version 1.0.0-alpha.32 addresses this issue. Patch name: 5f7315e05852faf3a9c177c0a34f9ea9b0371d3d. It is recommended to upgrade the affected component."
    },
    {
      "lang": "es",
      "value": "Se ha encontrado una falla en DecoCMS Mesh hasta la versión 1.0.0-alpha.31. Afectada por esta vulnerabilidad es la función createTool del archivo packages/sdk/src/mcp/teams/api.ts del componente Workspace Domain Gestor. Esta manipulación del argumento domain causa controles de acceso inadecuados. El ataque puede iniciarse de forma remota. La complejidad de un ataque es bastante alta. La explotación parece ser difícil. El exploit ha sido publicado y puede ser utilizado. La actualización a la versión 1.0.0-alpha.32 soluciona este problema. Nombre del parche: 5f7315e05852faf3a9c177c0a34f9ea9b0371d3d. Se recomienda actualizar el componente afectado."
    }
  ],
  "lastModified": "2026-09-30T23:10:00.237",
  "sourceIdentifier": "cna@vuldb.com"
}