CVE-2025-29766: Tuleap has missing CSRF protections on artifact submission & edition from the tracker view
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29766?
CVE-2025-29766 is classified as a moderate severity vulnerability due to the potential for unauthorized artifact submissions and edits.
How do I fix CVE-2025-29766?
To fix CVE-2025-29766, upgrade Tuleap to the latest version that addresses the missing CSRF protections.
What software versions are affected by CVE-2025-29766?
CVE-2025-29766 affects Tuleap Community Edition versions up to 16.5.99.1741784483 and Tuleap Enterprise Edition versions between 16.4-8 and 16.5-3.
What are the potential impacts of CVE-2025-29766?
An attacker could exploit CVE-2025-29766 to trick users into submitting or editing artifacts without their consent.
Is there a workaround for CVE-2025-29766?
There is no official workaround for CVE-2025-29766, updating to a patched version is recommended.