CVE-2025-53902: Tuleap exposes artifacts to a mentioned user via email notifications
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not authorized to view. This is fixed in Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53902?
CVE-2025-53902 has been classified as a high severity vulnerability due to potential unauthorized access to confidential information.
How do I fix CVE-2025-53902?
To address CVE-2025-53902, upgrade Tuleap Community Edition to version 16.9.99.1752585665 or Tuleap Enterprise Edition to versions 16.8-6 and 16.9-5 or later.
What versions are affected by CVE-2025-53902?
CVE-2025-53902 affects Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to versions 16.8-6 and 16.9-5.
What type of information is at risk in CVE-2025-53902?
CVE-2025-53902 could allow unauthorized users to access confidential project information stored in Tuleap.
Is CVE-2025-53902 present in the latest Tuleap editions?
No, CVE-2025-53902 has been resolved in the latest editions of Tuleap after the specified version updates.