{"id":"CVE-2025-64760","title":"Tuleap is a free and open source suite for management of software development and collaboration","summary":"Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-352"],"vendor":"enalean","product":"tuleap","affected":["tuleap < 16.13-8","tuleap < 17.0.99.1763126988","tuleap >= 17.0, < 17.0-3"],"patched":["tuleap 17.0-3"],"published":"2025-12-08","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64760","references":[{"url":"https://github.com/Enalean/tuleap/commit/71d427b0f7ed8fa269a5ee6f7a557cf3dfc99cd4","label":"security-advisories@github.com"},{"url":"https://github.com/Enalean/tuleap/security/advisories/GHSA-f2xv-x3g6-4j9p","label":"security-advisories@github.com"},{"url":"https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=71d427b0f7ed8fa269a5ee6f7a557cf3dfc99cd4","label":"security-advisories@github.com"},{"url":"https://tuleap.net/plugins/tracker/?aid=45618","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00145,"epssPercentile":0.0323,"ingestedAt":"2026-10-07T20:46:46.778Z","slug":"CVE-2025-64760","body":"## Overview\n\nTuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This issue is fixed in Tuleap Community Edition version 17.0.99.1763126988 and Tuleap Enterprise Edition versions 17.0-3 and 16.13-8.\n\n## Affected\n\n- `tuleap < 16.13-8`\n- `tuleap < 17.0.99.1763126988`\n- `tuleap >= 17.0, < 17.0-3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tuleap 17.0-3`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}