VulnerabilityAnalyzed
CVE-2026-24007
Tuleap is missing CSRF protection in the Overview inconsistent items.
MEDIUM 4.6EPSS 0.14%
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is fixed in Tuleap Community Edition 17.0.99.1768924735 and Tuleap Enterprise Edition 17.2-5, 17.1-6, and 17.0-9.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- enalean/tuleap
- Source
- security-advisories@github.com
References
- https://github.com/Enalean/tuleap/commit/5ec5e81e409892fe0e41f11d5d36ee6c85a6fbb5Patch
- https://github.com/Enalean/tuleap/security/advisories/GHSA-7g48-rwqj-ffxwPatch, Vendor Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=5ec5e81e409892fe0e41f11d5d36ee6c85a6fbb5Broken Link
- https://tuleap.net/plugins/tracker/?aid=46389Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.