VULNERABILITY INTELLIGENCE

CVE-2025-69288

CVSS score9.1 CRITICAL
EPSS probability0.85%
CISA KEVNot currently listed
Published2025-12-31
Last modified2026-09-23
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references