PT-2025-51111 · Git+1 · Python-Utcp+1
Published
2025-12-13
·
Updated
2025-12-18
·
CVE-2025-14542
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
(affected versions not specified)
Description
The issue occurs when a client retrieves a tools’ JSON specification, referred to as a Manual, from a remote Manual Endpoint. A provider can initially deliver a harmless manual, establishing client trust, but subsequently alter the manual to exploit the client. This allows a malicious provider to change the manual after the client has begun to trust the provider.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python-Utcp
Utcp