CVE-2025-53541 Details
Description
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.
A cross-site scripting (XSS) vulnerability has been identified in Tuleap, affecting both the Community and Enterprise Editions. In versions prior to Tuleap Community Edition 16.9.99.1751892857 and Tuleap Enterprise Edition 16.8-5 and 16.9-3, malicious users could exploit this vulnerability by injecting harmful code into certain artifacts. When the children of a parent artifact were displayed, this injected code could be executed by unsuspecting users. The issue has been addressed in the latest versions of both editions.
Users can upgrade to Tuleap Community Edition 16.9.99.1751892857 or Tuleap Enterprise Edition 16.9-3 or 16.8-5 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| enalean tuleap | < 16.8-5 < 16.9.99.1751892857 >= 16.9, < 16.9-3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | New CVE Received | [email protected] |
| Jul 29, 2025 | CVE Modified | CISA-ADP |