---
id: CVE-2025-64497
title: >-
  Tuleap is an Open Source Suite for management of software development and
  collaboration
summary: >-
  Tuleap is an Open Source Suite for management of software development and
  collaboration. Versions below 17.0.99.1762431347 of  Tuleap Community Edition
  and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow
  attackers to a…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: enalean
product: tuleap
affected:
  - tuleap < 16.12-10
  - tuleap < 17.0.99.1762431347
  - 'tuleap >= 16.13, < 16.13-7'
  - 'tuleap >= 17.0, < 17.0-2'
patched:
  - tuleap 17.0-2
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64497'
references:
  - url: >-
      https://github.com/Enalean/tuleap/commit/403eb69f4cfafe52254c8f9bdbe66e1fedadc254
    label: security-advisories@github.com
  - url: 'https://github.com/Enalean/tuleap/security/advisories/GHSA-v6vm-6rxf-7p2v'
    label: security-advisories@github.com
  - url: >-
      https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=403eb69f4cfafe52254c8f9bdbe66e1fedadc254
    label: security-advisories@github.com
  - url: 'https://tuleap.net/plugins/tracker/?aid=45583'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00279
epssPercentile: 0.18563
ingestedAt: '2026-10-07T20:46:46.777Z'
---

## Overview

Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of  Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This issue is fixed in version 17.0.99.1762431347 of the Tuleap Community Edition and versions 17.0-2, 16.13-7 and 16.12-10 of Tuleap Enterprise Edition.

## Affected

- `tuleap < 16.12-10`
- `tuleap < 17.0.99.1762431347`
- `tuleap >= 16.13, < 16.13-7`
- `tuleap >= 17.0, < 17.0-2`

## Remediation

Upgrade past the affected range:

- `tuleap 17.0-2`
