{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "16.4-8"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "16.5.99.1741784483"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "16.5"
              },
              {
                "fixed": "16.5-3"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "81f45330fdcc1329cc71eddf4d04b80c340b3b93"
            }
          ],
          "repo": "https://github.com/enalean/tuleap",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-6p9q-p2q4-3rqx"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-352"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29766.json"
  },
  "details": "Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission \u0026 edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.",
  "id": "CVE-2025-29766",
  "modified": "2026-03-13T21:57:41.084355320Z",
  "published": "2025-03-31T15:38:00.273Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29766.json"
    },
    {
      "type": "FIX",
      "url": "https://github.com/Enalean/tuleap/commit/81f45330fdcc1329cc71eddf4d04b80c340b3b93"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/Enalean/tuleap/security/advisories/GHSA-6p9q-p2q4-3rqx"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29766"
    },
    {
      "type": "WEB",
      "url": "https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit\u0026h=81f45330fdcc1329cc71eddf4d04b80c340b3b93"
    },
    {
      "type": "WEB",
      "url": "https://tuleap.net/plugins/tracker/?aid=42208"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Tuleap has missing CSRF protections on artifact submission \u0026 edition from the tracker view"
}