VULNERABILITY INTELLIGENCE
CVE-2025-69288
CVSS score9.1 CRITICAL
EPSS probability0.85%
CISA KEVNot currently listed
Published2025-12-31
Last modified2026-09-23
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- security-advisories@github.com — Patch
- security-advisories@github.com — Release Notes
- security-advisories@github.com — Exploit, Mitigation, Vendor Advisory
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 — Exploit, Mitigation, Vendor Advisory