CVE-2025-60786: Kagilum Icescrum

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.

Affected products

  • Kagilum Icescrum: up to and including 7.54

Published 2025-12-15. Last modified 2026-10-07.