Code Injection Vulnerability in Tuleap Community and Enterprise Editions
CVE-2025-53541
What is CVE-2025-53541?
A code injection vulnerability exists in the Tuleap platform, affecting both Community and Enterprise Editions. Malicious users with limited control over specific artifacts can exploit this flaw to inject and execute arbitrary code when displaying child artifacts. Users are advised to upgrade to the patched versions (Tuleap Community Edition 16.9.99.1751892857 and Tuleap Enterprise Editions 16.8-5 and 16.9-3) to mitigate risks associated with this vulnerability.
Affected Version(s)
tuleap Tuleap Community Edition < 16.9.99.1751892857 < Tuleap Community Edition 16.9.99.1751892857
tuleap Tuleap Enterprise Edition >= 16.9, < 16.9-3 < Tuleap Enterprise Edition 16.9, 16.9-3
tuleap Tuleap Enterprise Edition < 16.8-5 < Tuleap Enterprise Edition 16.8-5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
