{"id":"CVE-2025-69288","summary":"Titra has Remote Code Execution in Admin Functionality","details":"Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.","aliases":["GHSA-pqgx-6wg3-gmvr"],"modified":"2026-08-27T03:57:05.302500653Z","published":"2025-12-31T21:55:44.667Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69288.json"},"references":[{"type":"WEB","url":"https://github.com/kromitgmbh/titra/releases/tag/0.99.49"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69288.json"},{"type":"ADVISORY","url":"https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69288"},{"type":"FIX","url":"https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/titraio/titra","events":[{"introduced":"0"},{"fixed":"2e2ac5cbeed47a76720b21c7fde0214a242e065e"}],"database_specific":{"cpe":"cpe:2.3:a:kromit:titra:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.99.49"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["0.99.48","0.99.47","0.99.46","0.99.45","0.99.44","0.99.43","0.99.42","0.99.41","0.99.40","0.99.39","0.99.38","0.99.37","0.99.36","0.99.35","0.99.34","0.99.33","0.99.32","0.99.31","0.99.30","0.99.29","0.99.28","0.99.27","0.99.26","0.99.25","0.99.24","0.99.23","0.99.22","0.99.21","0.99.20","0.99.19","0.99.18","0.99.17","0.99.16","0.99.15","0.99.14","0.99.13","0.99.12","0.99.11","0.99.10","0.99.9","0.99.4","0.99.3","0.99.2","0.99.1","0.99.0","0.98.2","0.98.1","0.98.0","0.97.4","0.97.3","0.97.2","0.97.1","0.97.0","0.96.11","0.96.9","0.96.8","0.96.7","0.96.6","0.96.5","0.96.4","0.96.3","0.96.2","0.96.1","0.96.0","0.95.11","0.95.10","0.95.9","0.95.8","0.95.6","0.95.5","0.95.4","0.95.3","0.95.2","0.95.1","0.95.0","0.94.4","0.94.3","0.94.2","0.94.1","0.94.0","0.93.2","0.93.1","0.93.0","0.92.1","0.92.0","0.91.0","0.89.2","0.89.1","0.89.0","0.88.1","0.88.0","0.87.0","0.86.0","0.85.0","0.84.0","0.83.0","0.82.0","0.81.0","0.80.8","0.80.7","0.80.6","0.80.5","0.80.4","0.80.3","0.80.2","0.80.1","0.80.0","0.79.3","0.79.2","0.79.1","0.79.0","0.78.1","0.78.0","0.77.1","0.77.0","0.76.1","0.76.0","0.75.1","0.75.0","0.74.3","0.74.2","0.74.1","0.74.0","0.73.0","0.72.1","0.72.0","0.71.1","0.71.0","0.70.2","0.70.1","0.70.0","0.69.0","0.68.0","0.67.0","0.66.0","0.65.0","0.64.0","0.63.0","0.62.2","0.62.1","0.62.0","0.61.0","0.60.2","0.60.1","0.60.0","0.59.1","0.59.0","0.58.0","0.57.0","0.56.0","0.55.0","0.54.0","0.53.0","0.52.0","0.51.0","0.50.0","0.49.0","0.48.0","0.47.0","0.46.0","0.45.0","0.44.1","0.44.0","0.43.0","0.41.0","0.40.2","0.40.1","0.40.0","0.35.0","0.34.0","0.33.0","0.32.0","0.31.0","0.30.1","0.30.0","0.29.0","0.28.0","0.27.0","0.26.1","0.26.0","0.25.0","0.24.1","0.24.0","0.23.1","0.23.0","0.22.1","0.22.0","0.21.0","0.20.1","0.20.0","0.19.1","0.19.0","0.18.0","0.17.0","0.16.3","0.16.2","0.16.1","0.16.0","0.15.1","0.15.0","0.14.0","0.13.2","0.13.1","0.13.0","0.12.0","0.11.0","0.10.0","0.9.10","0.9.9","0.9.8","0.9.7","0.9.6","0.9.5","0.9.4","0.9.3","0.9.2","0.9.1","0.9.0","0.8.9","0.8.8","0.8.7","0.8.6","0.8.5","0.8.4","0.8.3","0.8.2","0.8.1","0.8.0","0.7.0","0.6.2","0.6.1","0.6.0","0.5.1","0.5.0","0.4.1","0.4.0","0.3.0","0.2.0","0.1.0","v0.0.2-alpha","v0.0.1-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69288.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}