CVE-2025-53073 Details
Description
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).
A vulnerability in Sentry versions 25.1.0 through 25.5.1 allows authenticated attackers to perform unauthorized actions on a project's issue endpoint. This includes actions such as adding comments, without being a member of the project's team. The vulnerability requires knowledge of a seven-digit issue ID, which is not confidential and may be publicly available or predictable.
Users are advised to upgrade to Sentry version 25.6.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2025CISA-ADP
Assessed Jun 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getsentry/self-hosted/releases | [email protected] | Release NotesVendor |
| https://github.com/nikolas-ch/CVEs/blob/main/Sentry_Version%3E%3D25.1.0/Sentry_%3E%3D25.1.0_WeakAuthorizationControl.txt | [email protected] | Technical Description |
| https://github.com/nikolas-ch/CVEs/tree/main/Sentry_Version%3E%3D25.1.0 | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sentry | >= 25.1.0, <= 25.5.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | New CVE Received | [email protected] |
Volerion