VYPR
Unrated severityOSV Advisory· Published Dec 16, 2025· Updated Dec 17, 2025

GLPI vulnerable to unauthorized access to restricted Knowledge Base items through the API

CVE-2025-64520

Description

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.