VYPR
Medium severity4.9NVD Advisory· Published Jan 4, 2026· Updated Apr 15, 2026

CVE-2025-14830

CVE-2025-14830

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2025-14830: Stored XSS in JFrog Artifactory Workers versions ≥7.94.0 and <7.117.10 allows attackers to inject arbitrary web scripts.

Vulnerability

Overview

CVE-2025-14830 is a stored cross-site scripting (XSS) vulnerability in the JFrog Artifactory Workers module. The flaw stems from improper neutralization of user-controlled input during web page generation, specifically within the Workers functionality. This permits an attacker to inject malicious scripts that are later served to other users [1].

Exploitation

Prerequisites

An attacker must have the ability to supply crafted input to an Artifactory Workers endpoint that reflects or stores the payload without sanitization. No special network position is required beyond standard web access to the affected service. User interaction (e.g., viewing a page containing the injected payload) is necessary for script execution [1].

Impact

Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user within the Artifactory web interface [1].

Mitigation

Status

JFrog has addressed the vulnerability in Artifactory version 7.117.10 and later. Users running versions from 7.94.0 up to but not including 7.117.10 should upgrade immediately. No workarounds have been publicly documented [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.