Critical Vulnerability Information Vulnerability Title Missing CSRF protection on tracker canned responses administration Severity Level: Moderate CVSS v3 Base Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: Required - Scope: Unchanged - Confidentiality Impact: None - Integrity Impact: Low - Availability Impact: Low Impact CVE ID: CVE-2025-48991 Weakness: CWE-352 Affected Versions Tuleap Community Edition (tuleap): < 16.8.99.1748845907 Tuleap Enterprise Edition (tuleap): - < 16.8-3 - < 16.7-5 Fixed Versions Tuleap Community Edition: 16.8.99.1748845907 Tuleap Enterprise Edition: - 16.8-3 - 16.7-5 Description and Impact Description: Missing CSRF protection for administration of tracker canned responses. Impact: Attackers can exploit this vulnerability to trick victims into modifying canned responses. Patch Fixed versions are provided. Additional Information For any questions or comments, please contact us via the contact information provided on the Tuleap.org security page. References Request #43326 Commit cbf9b2a Stable branch commit