CVE-2025-49704:
This vulnerability arises from the implementation of the SurrogateSelector interface.
CVE-2025-49706 authentication bypass, allows import/update operations on SharePoint WebPart components via the ToolPane endpoint.
Accordingly, you can contact the @hawktrace