CVE-2025-53541
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://github.com/Enalean/tuleap/commit/c1aec8247697d63dc4af791ecd6bd70d105ded08
- https://github.com/Enalean/tuleap/security/advisories/GHSA-6r66-j76j-rwhw
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=c1aec8247697d63dc4af791ecd6bd70d105ded08
- https://tuleap.net/plugins/tracker/?aid=43693
- https://tuleap.net/plugins/tracker/?aid=43693
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-53541",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-53541",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-07-29T19:33:06.339978Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "Enalean",
"product": "tuleap",
"versions": [
{
"status": "affected",
"version": "Tuleap Community Edition < 16.9.99.1751892857"
},
{
"status": "affected",
"version": "Tuleap Enterprise Edition >= 16.9, < 16.9-3"
},
{
"status": "affected",
"version": "Tuleap Enterprise Edition < 16.8-5"
}
]
}
]
}
],
"published": "2025-07-29T20:15:28.500",
"references": [
{
"url": "http://github.com/Enalean/tuleap/commit/c1aec8247697d63dc4af791ecd6bd70d105ded08",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Enalean/tuleap/security/advisories/GHSA-6r66-j76j-rwhw",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=c1aec8247697d63dc4af791ecd6bd70d105ded08",
"tags": [
"Permissions Required"
],
"source": "security-advisories@github.com"
},
{
"url": "https://tuleap.net/plugins/tracker/?aid=43693",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://tuleap.net/plugins/tracker/?aid=43693",
"tags": [
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3."
},
{
"lang": "es",
"value": "Tuleap es una suite de código abierto creada para facilitar la gestión del desarrollo de software y la colaboración. En Tuleap Community Edition anterior a la versión 16.9.99.1751892857 y Tuleap Enterprise Edition anterior a las versiones 16.8-5 y 16.9-3, usuarios maliciosos con cierto control sobre ciertos artefactos podían insertar código malicioso al mostrar los elementos secundarios de un artefacto principal para obligar a las víctimas a ejecutar el código no controlado. Esto se ha corregido en Tuleap Community Edition anterior a la versión 16.9.99.1751892857 y Tuleap Enterprise Edition anterior a las versiones 16.8-5 y 16.9-3."
}
],
"lastModified": "2026-06-17T09:38:24.897",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E01F8ECA-7889-4EB9-9964-2E1E3B142847",
"versionEndExcluding": "16.8-5"
},
{
"criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "681D79D9-7B3D-44D7-9A3D-3CC449399F89",
"versionEndExcluding": "16.9.99.1751892857"
},
{
"criteria": "cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC079AB5-8BFF-4153-B103-1DE823E677BB",
"versionEndExcluding": "16.9-3",
"versionStartIncluding": "16.9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}