CVE-2025-48991: Tuleap missing CSRF protection on tracker canned responses administration
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned responses. Tuleap Community Edition 16.8.99.1748845907, Tuleap Enterprise Edition 16.8-3, and Tuleap Enterprise Edition 16.7-5 contain a fix for the vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48991?
CVE-2025-48991 has been classified as a vulnerability that could allow unauthorized actions by exploiting certain weaknesses in Tuleap.
How do I fix CVE-2025-48991?
To mitigate CVE-2025-48991, upgrade to Tuleap Community Edition version 16.8.99.1748845907 or Tuleap Enterprise Edition version 16.8-3 or 16.7-5.
What versions of Tuleap are affected by CVE-2025-48991?
CVE-2025-48991 affects Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5.
What type of attacks can CVE-2025-48991 enable?
CVE-2025-48991 could allow attackers to exploit the vulnerability to potentially trick users into performing unintended actions.
When was CVE-2025-48991 reported?
CVE-2025-48991 was reported and made publicly available through security advisories related to Tuleap security.