CVE-2025-58053: Galette

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.

Affected products

  • Galette Galette: before 1.2.0 (fixed in 1.2.0)

Published 2025-12-19. Last modified 2026-06-17.