---
id: CVE-2025-14517
title: A vulnerability was determined in Yalantis uCrop 2.2.11
summary: "A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity\_ of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only …"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-926
vendor: yalantis
product: ucrop
affected:
  - ucrop = 2.2.11
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14517'
references:
  - url: >-
      https://mesquite-dream-86b.notion.site/uCrop-Library-SSRF-and-Intent-Spoofing-2b8512562197804dae69edf96b942446#469832583e0444dcb3d08b0ca661d1c6
    label: cna@vuldb.com
  - url: >-
      https://mesquite-dream-86b.notion.site/uCrop-Library-SSRF-and-Intent-Spoofing-2b8512562197804dae69edf96b942446?source=copy_link
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.335855'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.335855'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702811'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.13632
ingestedAt: '2026-10-07T20:46:46.850Z'
---

## Overview

A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `ucrop = 2.2.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
