Key Information Summary Vulnerability Title: Missing CSRF protections in the management of tracker triggers Vulnerability Type: CSRF (Cross-Site Request Forgery) Severity: Moderate CVE ID: CVE-2025-64760 CWE ID: CWE-352 Affected Scope Affected Versions - Tuleap Community Edition: < 17.0.99.1763126988 - Tuleap Enterprise Edition: < 17.0-3, < 16.13-8 Fixed Versions - Tuleap Community Edition: 17.0.99.1763126988 - Tuleap Enterprise Edition: 17.0-3, 16.13-8 Impact and Severity Details CVSS v3 Score: 4.6 / 10 CVSS v3 Base Metrics - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: Required - Scope: Unchanged - Confidentiality Impact: None - Integrity Impact: Low - Availability Impact: Low Vulnerability Description Description: CSRF protections are missing when managing tracker triggers. Impact: An attacker may exploit this vulnerability to trick victims into creating or deleting tracker triggers. Remediation Specific fixed versions are available for both Tuleap Community and Enterprise Editions. Additional Information and References Contact information is available on Tuleap.org’s security page. Links to related vulnerability reports and code commits are provided.