createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argument domain causes improper access controls.This vulnerability is handled as CVE-2025-14660. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR