CVE-2025-64499
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-08

Last updated on: 2025-12-10

Assigner: GitHub, Inc.

Description
Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. Attackers have access to create, edit or remove plans. This issue is fixed in Tuleap Community Edition version 17.0.99.1762456922 and Tuleap Enterprise Edtion versions 17.0-2, 16.13-7 and 16.12-10.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-08
Last Modified
2025-12-10
Generated
2026-06-16
AI Q&A
2025-12-09
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
tuleap tuleap_enterprise_edition *
tuleap tuleap_community_edition *
enalean tuleap to 16.12-10 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in Tuleap's planning management API. It allows attackers to create, edit, or remove plans without proper authorization by tricking authenticated users into executing unwanted actions.

Impact Analysis

An attacker exploiting this vulnerability can manipulate planning data by creating, editing, or deleting plans, potentially disrupting project management and collaboration workflows. This could lead to loss of data integrity and availability.

Mitigation Strategies

To mitigate this vulnerability, upgrade Tuleap to Community Edition version 17.0.99.1762456922 or later, or Enterprise Edition versions 17.0-2, 16.13-7, or 16.12-10 or later. These versions contain the fix for the CSRF vulnerability in the planning management API.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-64499. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart