Medium severity4.3NVD Advisory· Published Nov 30, 2025· Updated Jun 17, 2026
CVE-2025-66422
CVE-2025-66422
Description
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
trytondPyPI | >= 7.5.0, < 7.6.11 | 7.6.11 |
trytondPyPI | >= 7.1.0, < 7.4.21 | 7.4.21 |
trytondPyPI | >= 7.0.0, < 7.0.40 | 7.0.40 |
trytondPyPI | < 6.0.70 | 6.0.70 |
Affected products
3Patches
Vulnerability mechanics
References
4- foss.heptapod.net/tryton/tryton/-/issues/14354nvdExploitIssue TrackingWEB
- discuss.tryton.org/t/security-release-for-issue-14354/8950nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-jqfc-9q34-prhgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-66422ghsaADVISORY
News mentions
0No linked articles in our index yet.