Get real-time updates on Telegram
CVE-2025-14660: Mesh 1.0.0-alpha.0, 1.0.0-alpha.1, 1.0.0-alpha.2, 1.0.0-alpha.3, 1.0.0-alpha.4, 1.0.0-alpha.5, 1.0.0-alpha.6…
CVE-2025-14660. CVSS 3.1 base score 5.6 (MEDIUM, Vendor/CNA). EPSS 0.00323 (percentile 0.23284), scored 2026-10-06.
Affected technology
Mesh · 1.0.0-alpha.0, 1.0.0-alpha.1, 1.0.0-alpha.2, 1.0.0-alpha.3, 1.0.0-alpha.4, 1.0.0-alpha.5, 1.0.0-alpha.6, 1.0.0-alpha.7, 1.0.0-alpha.8, 1.0.0-alpha.9, 1.0.0-alpha.10, 1.0.0-alpha.11, 1.0.0-alpha.12, 1.0.0-alpha.13, 1.0.0-alpha.14, 1.0.0-alpha.15, 1.0.0-alpha.16, 1.0.0-alpha.17, 1.0.0-alpha.18, 1.0.0-alpha.19, 1.0.0-alpha.20, 1.0.0-alpha.21, 1.0.0-alpha.22, 1.0.0-alpha.23, 1.0.0-alpha.24, 1.0.0-alpha.25, 1.0.0-alpha.26, 1.0.0-alpha.27, 1.0.0-alpha.28, 1.0.0-alpha.29, 1.0.0-alpha.30, 1.0.0-alpha.31
DecoCMS
Description’s affected range: up to 1.0.0-alpha.31
Component: Workspace Domain Handler
Function: createTool
File: packages/sdk/src/mcp/teams/api.ts
Attack conditions (VulDB, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
VulDB’s CVSS 4.0 assessment (base score 2.9/10) rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
Patch identifier: 5f7315e05852faf3a9c177c0a34f9ea9b0371d3d
- CWE
- CWE-266, CWE-284
- CCR priority
- 22.5 /100 (P4)
- CVSS 3.1
- 5.6 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L · Vendor/CNA
- EPSS
- 0.00323 · percentile 0.23284 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 19:17:20.510062+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-14660.html