CVE-2025-11273
MEDIUMLaChatterie Verger <1.2.10 - SSRF
Title source: llmDescription
A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL results in deserialization. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Scores
CVSS v3
6.3
EPSS
0.0007
EPSS Percentile
20.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
CWE-20
Status
draft
Timeline
Published
Oct 04, 2025
Tracked Since
Feb 18, 2026