{"id":"CVE-2025-53073","details":"In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).","modified":"2026-08-12T03:51:14.250724156Z","published":"2025-06-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-425"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53073.json"},"references":[{"type":"WEB","url":"https://github.com/nikolas-ch/CVEs/blob/main/Sentry_Version%3E%3D25.1.0/Sentry_%3E%3D25.1.0_WeakAuthorizationControl.txt"},{"type":"WEB","url":"https://github.com/nikolas-ch/CVEs/tree/main/Sentry_Version%3E%3D25.1.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53073.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53073"},{"type":"PACKAGE","url":"https://github.com/getsentry/self-hosted/releases"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getsentry/self-hosted","events":[{"introduced":"11faae66acdc6a1dcbc72a09d8ee316f52daeadb"},{"fixed":"cbebc4f3f43a6ef5834d059bb144e67b7515d752"}],"database_specific":{"extracted_events":[{"introduced":"25.1.0"},{"last_affected":"25.5.1"},{"fixed":"25.5.1"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53073.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}