{"id":"CVE-2025-64498","title":"Tuleap is an Open Source Suite for management of software development and collaboration","summary":"Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to  17.0-2, 16.13-7 and 16.12-10 allow attac…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-352"],"vendor":"enalean","product":"tuleap","affected":["tuleap < 16.12-10","tuleap < 17.0.99.1762444754","tuleap >= 16.13, < 16.13-7","tuleap >= 17.0, < 17.0-2"],"patched":["tuleap 17.0-2"],"published":"2025-12-08","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64498","references":[{"url":"https://github.com/Enalean/tuleap/commit/993316dd6a291bb3937cb7a4571eaab0e7d55370","label":"security-advisories@github.com"},{"url":"https://github.com/Enalean/tuleap/security/advisories/GHSA-vxfh-h8p6-p5rg","label":"security-advisories@github.com"},{"url":"https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=993316dd6a291bb3937cb7a4571eaab0e7d55370","label":"security-advisories@github.com"},{"url":"https://tuleap.net/plugins/tracker/?aid=45593","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00145,"epssPercentile":0.0323,"ingestedAt":"2026-10-07T20:46:46.778Z","slug":"CVE-2025-64498","body":"## Overview\n\nTuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to  17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in version Tuleap Community Edition version 17.0.99.1762444754 and Tuleap Enterprise Edition versions 17.0-2, 16.13-7 and 16.12-10.\n\n## Affected\n\n- `tuleap < 16.12-10`\n- `tuleap < 17.0.99.1762444754`\n- `tuleap >= 16.13, < 16.13-7`\n- `tuleap >= 17.0, < 17.0-2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tuleap 17.0-2`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}