CVE-2025-14830
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2025-14830: Stored XSS in JFrog Artifactory Workers versions ≥7.94.0 and <7.117.10 allows attackers to inject arbitrary web scripts.
Vulnerability
Overview
CVE-2025-14830 is a stored cross-site scripting (XSS) vulnerability in the JFrog Artifactory Workers module. The flaw stems from improper neutralization of user-controlled input during web page generation, specifically within the Workers functionality. This permits an attacker to inject malicious scripts that are later served to other users [1].
Exploitation
Prerequisites
An attacker must have the ability to supply crafted input to an Artifactory Workers endpoint that reflects or stores the payload without sanitization. No special network position is required beyond standard web access to the affected service. User interaction (e.g., viewing a page containing the injected payload) is necessary for script execution [1].
Impact
Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user within the Artifactory web interface [1].
Mitigation
Status
JFrog has addressed the vulnerability in Artifactory version 7.117.10 and later. Users running versions from 7.94.0 up to but not including 7.117.10 should upgrade immediately. No workarounds have been publicly documented [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >=7.94.0, <7.117.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.