Medium severity6.5NVD Advisory· Published Nov 30, 2025· Updated Jun 17, 2026
CVE-2025-66424
CVE-2025-66424
Description
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
trytondPyPI | >= 7.5.0, < 7.6.11 | 7.6.11 |
trytondPyPI | >= 7.1.0, < 7.4.21 | 7.4.21 |
trytondPyPI | >= 7.0.0, < 7.0.40 | 7.0.40 |
trytondPyPI | >= 6.0.0, < 6.0.70 | 6.0.70 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-2w93-qwpp-vgvjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-66424ghsaADVISORY
- discuss.tryton.org/t/security-release-for-issue-14366/8953nvdIssue TrackingWEB
- foss.heptapod.net/tryton/tryton/-/issues/14366nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.