VYPR
Medium severity4.6NVD Advisory· Published Mar 31, 2025· Updated Jun 17, 2026

CVE-2025-29766

CVE-2025-29766

Description

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Enalean/Tuleap4 versions
    cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*+ 3 more
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*range: <16.5.99.1741784483
    • cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*range: <16.4-8
    • (no CPE)range: Community Edition < 16.5.99.1741784483, Enterprise Edition < 16.5-3, Enterprise Edition < 16.4-8
    • (no CPE)range: < 16.5.99.1741784483
  • Tuleap/Tuleapllm-fuzzy
    Range: Community Edition < 16.5.99.1741784483, Enterprise Edition < 16.5-3, Enterprise Edition < 16.4-8

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.