Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.
History

Tue, 05 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:enalean:tuleap:*:*:*:*:community:*:*:*
cpe:2.3:a:enalean:tuleap:*:*:*:*:enterprise:*:*:*

Wed, 30 Jul 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Enalean
Enalean tuleap
Vendors & Products Enalean
Enalean tuleap

Tue, 29 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Jul 2025 19:30:00 +0000

Type Values Removed Values Added
Description Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.
Title Tuleap is vulnerable to XSS attacks when displaying the children of a parent artifact
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-29T19:27:38.787Z

Updated: 2025-07-29T19:33:08.778Z

Reserved: 2025-07-02T15:15:11.515Z

Link: CVE-2025-53541

cve-icon Vulnrichment

Updated: 2025-07-29T19:33:02.810Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-29T20:15:28.500

Modified: 2025-08-05T14:19:08.840

Link: CVE-2025-53541

cve-icon Redhat

No data.