CVE-2025-14700: critical vulnerability in Arcadia Technology, LLC Crafty Controller
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
Published
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.9epss 6.6%
from disclosure to weapon0 days
Published on NVDDec 17
1st PoCDec 17
exploitation probability
6.6%top 6% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In short
A flaw in Crafty Controller's webhook feature lets authenticated users inject harmful code through templates, allowing them to execute commands on the server remotely.
Technical detail
CWE-1336 vulnerability in the Webhook Template component permits Server Side Template Injection (SSTI) when user-supplied input is not properly neutralized before template processing. An authenticated attacker can inject malicious template directives to achieve remote code execution on the affected system.
Summary generated and translated by AI from the official description.
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Arcadia Technology, LLC · Crafty Controllerpublic PoCs found — 2
githubgithub.com/Nosiume/CVE-2025-14700-poc★ 1githubgithub.com/secdongle/POC_CVE-2025-14700★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Arcadia Technology, LLC Crafty Controller
In the same product, most dangerous first.
CVE-2024-1064HIGHImproper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4EPSS 0.8%CVE-2026-13716CRITICALPath Traversal: '.../...//' in Crafty ControllerEPSS 0.8%CVE-2026-0963CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty ControllerEPSS 0.8%CVE-2026-0805HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty ControllerEPSS 0.7%CVE-2026-5652CRITICALAuthorization Bypass Through User-Controlled Key in Crafty ControllerEPSS 0.5%CVE-2025-14701HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty ControllerEPSS 0.3%