VYPR
Critical severity9.1OSV Advisory· Published Dec 31, 2025· Updated Jun 17, 2026

CVE-2025-69288

CVE-2025-69288

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Kromitgmbh/TitraOSV2 versions
    0.1.0, 0.10.0, 0.11.0, …+ 1 more
    • (no CPE)range: 0.1.0, 0.10.0, 0.11.0, …
    • (no CPE)range: <0.99.49
  • cpe:2.3:a:kromit:titra:*:*:*:*:*:*:*:*
    Range: <0.99.49

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.