PT-2025-40781 · Unknown · Lachatterie Verger
Wxhwxhwxh_Mie
·
Published
2025-10-04
·
Updated
2025-10-04
·
CVE-2025-11273
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LaChatterie Verger versions up to 1.2.10
Description
A flaw exists in LaChatterie Verger that impacts the
redirectToAuthorization function within the /src/main/services/mcp/oauth/provider.ts file. Manipulation of the URL argument leads to deserialization, and the attack can be carried out remotely. The exploit has been publicly released.Recommendations
Versions prior to 1.2.10 should be updated. As a temporary workaround, consider restricting access to the
/src/main/services/mcp/oauth/provider.ts file.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lachatterie Verger