Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e | Patch |
| https://github.com/kromitgmbh/titra/releases/tag/0.99.49 | Release Notes |
| https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr | Exploit Vendor Advisory Mitigation |
| https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr | Exploit Vendor Advisory Mitigation |
Configurations
History
No history.
Information
Published : 2025-12-31 22:15
Updated : 2026-01-13 15:25
NVD link : CVE-2025-69288
Mitre link : CVE-2025-69288
CVE.ORG link : CVE-2025-69288
JSON object : View
Products Affected
kromit
- titra
CWE
