CVE-2025-29766
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 352
Summary
CVE-2025-29766 is a vulnerability affecting Tuleap, an open-source software development and collaboration suite. The issue resides in the lack of Cross-Site Request Forgery (CSRF) protection during artifact submission and editing via the tracker view. An attacker can exploit this vulnerability to manipulate victims into submitting or editing artifacts and associated comments, posing a threat to data integrity. The vulnerability has been addressed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Editions 16.5-3 and 16.4-8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.