CVE 6.3 MEDIUM

DecoCMS Mesh Workspace Domain api.ts createTool access control_CVE-2025-14660

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access controls. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been published and may be used. Upgrading to version 1.0.0-alpha.32 addresses this issue. Patch name: 5f7315e05852faf3a9c177c0a34f9ea9b0371d3d. It is recommended to upgrade the affected component.

Basic Information

ID CVE-2025-14660
Source VulDB
Published Dec 14, 2025 at 12:32

Affected Product

Vendor DecoCMS
Product Mesh
Version 1.0.0-alpha.0
Affected Versions DecoCMS Mesh 1.0.0-alpha.0
DecoCMS Mesh 1.0.0-alpha.1
DecoCMS Mesh 1.0.0-alpha.2
DecoCMS Mesh 1.0.0-alpha.3
DecoCMS Mesh 1.0.0-alpha.4
DecoCMS Mesh 1.0.0-alpha.5
DecoCMS Mesh 1.0.0-alpha.6
DecoCMS Mesh 1.0.0-alpha.7
DecoCMS Mesh 1.0.0-alpha.8
DecoCMS Mesh 1.0.0-alpha.9
DecoCMS Mesh 1.0.0-alpha.10
DecoCMS Mesh 1.0.0-alpha.11
DecoCMS Mesh 1.0.0-alpha.12
DecoCMS Mesh 1.0.0-alpha.13
DecoCMS Mesh 1.0.0-alpha.14
DecoCMS Mesh 1.0.0-alpha.15
DecoCMS Mesh 1.0.0-alpha.16
DecoCMS Mesh 1.0.0-alpha.17
DecoCMS Mesh 1.0.0-alpha.18
DecoCMS Mesh 1.0.0-alpha.19
DecoCMS Mesh 1.0.0-alpha.20
DecoCMS Mesh 1.0.0-alpha.21
DecoCMS Mesh 1.0.0-alpha.22
DecoCMS Mesh 1.0.0-alpha.23
DecoCMS Mesh 1.0.0-alpha.24
DecoCMS Mesh 1.0.0-alpha.25
DecoCMS Mesh 1.0.0-alpha.26
DecoCMS Mesh 1.0.0-alpha.27
DecoCMS Mesh 1.0.0-alpha.28
DecoCMS Mesh 1.0.0-alpha.29
DecoCMS Mesh 1.0.0-alpha.30
DecoCMS Mesh 1.0.0-alpha.31

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.