CVE-2025-53073: Medium severity Sentry sentry vulnerability

Published Jun 24, 2025
·
Updated

In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).

Affected Software

1 affected component
Sentry sentry>=25.1.0<=25.5.1

Event History

Jun 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
May 13, 57455
Event
via FIRST·04:59 AM

Frequently Asked Questions

1

What is the severity of CVE-2025-53073?

CVE-2025-53073 is classified as a high severity vulnerability due to its potential for unauthorized access and actions on a project's issue endpoint.

2

How do I fix CVE-2025-53073?

To fix CVE-2025-53073, update Sentry to version 25.5.2 or later, which addresses this authorization flaw.

3

Which versions of Sentry are affected by CVE-2025-53073?

CVE-2025-53073 affects Sentry versions from 25.1.0 through 25.5.1.

4

What type of attack is associated with CVE-2025-53073?

CVE-2025-53073 allows an authenticated attacker to conduct unauthorized actions, such as adding comments to issues they are not a member of.

5

Can CVE-2025-53073 be exploited without knowledge of the project team?

Yes, an attacker can exploit CVE-2025-53073 without being a member of the project's team, as long as they know the seven-digit issue ID.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203