Description
The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endpoint. While a provider may initially serve a benign manual (e.g., one defining an HTTP tool call), earning the clients’ trust, a malicious provider can later change the manual to exploit the client.
Problem types
CWE-501 Trust Boundary Violation
Product status
References
research.jfrog.com/...command-execution-jfsa-2025-001648329/
github.com/...ommit/2dc9c02df72cad3770c934959325ec344b441444
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.