Home

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

PUBLISHED Reserved 2025-12-31 | Published 2025-12-31 | Updated 2026-01-02 | Assigner GitHub_M




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-20: Improper Input Validation

Product status

< 0.99.49
affected

References

github.com/.../titra/security/advisories/GHSA-pqgx-6wg3-gmvr exploit

github.com/.../titra/security/advisories/GHSA-pqgx-6wg3-gmvr

github.com/...ommit/2e2ac5cbeed47a76720b21c7fde0214a242e065e

github.com/kromitgmbh/titra/releases/tag/0.99.49

cve.org (CVE-2025-69288)

nvd.nist.gov (CVE-2025-69288)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.