CVE-2025-64760: Enalean Tuleap

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This issue is fixed in Tuleap Community Edition version 17.0.99.1763126988 and Tuleap Enterprise Edition versions 17.0-3 and 16.13-8.

Affected products

  • Enalean Tuleap: before 16.13-8 (fixed in 16.13-8); before 17.0.99.1763126988 (fixed in 17.0.99.1763126988); from 17.0, before 17.0-3 (fixed in 17.0-3)

Published 2025-12-08. Last modified 2026-10-07.