CVE-2025-14700

Publication date

2025-12-17 00:04:37

Family

GitLab

State

PUBLISHED

Description

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.