CVE-2025-27099: Tuleap allows XSS via the tracker names used in the semantic timeframe deletion message
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force other tracker administrators to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740067916 and Tuleap Enterprise Edition 16.4-5 and 16.3-10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tuleap Community Editionto a version that resolves this vulnerability.Fixed in 16.4.99.1740067916 - Upgrade
Upgrade
Tuleap Enterprise Editionto a version that resolves this vulnerability.Fixed in 16.4-5 - Upgrade
Upgrade
Tuleap Enterprise Editionto a version that resolves this vulnerability.Fixed in 16.3-10
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27099?
CVE-2025-27099 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS).
How do I fix CVE-2025-27099?
To fix CVE-2025-27099, update Tuleap to the latest version or apply any available security patches provided by the vendor.
What is affected by CVE-2025-27099?
CVE-2025-27099 affects Tuleap Community Edition versions up to 16.4.99.1740067916 and specific versions of Tuleap Enterprise Edition.
What type of vulnerability is CVE-2025-27099?
CVE-2025-27099 is a cross-site scripting (XSS) vulnerability related to tracker names in Tuleap.
Who can exploit CVE-2025-27099?
CVE-2025-27099 can be exploited by any user with tracker administration rights if they use a semantic timeframe shared by other trackers.