---
id: CVE-2025-69288
title: Titra is open source project time tracking software
summary: >-
  Titra is open source project time tracking software. Prior to version 0.99.49,
  Titra allows any authenticated Admin user to modify the timeEntryRule in the
  database. The value is then passed to a NodeVM value to execute as code.
  Without …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: kromit
product: titra
affected:
  - titra < 0.99.49
patched:
  - titra 0.99.49
published: '2025-12-31'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69288'
references:
  - url: >-
      https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e
    label: security-advisories@github.com
  - url: 'https://github.com/kromitgmbh/titra/releases/tag/0.99.49'
    label: security-advisories@github.com
  - url: >-
      https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr
    label: security-advisories@github.com
  - url: >-
      https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00832
epssPercentile: 0.56117
ingestedAt: '2026-09-23T14:25:29.785Z'
---

## Overview

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

## Affected

- `titra < 0.99.49`

## Remediation

Upgrade past the affected range:

- `titra 0.99.49`
