PT-2025-44030 · Unknown · Turbotenant

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-62516

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TurboTenant versions prior to 2.0.0
Description A security issue exists in the TurboTenant landlord onboarding and rental signup system, specifically within the property listing activation workflow. This issue could allow unauthorized access to Stripe payment session data, potentially exposing sensitive business metadata, including landlord dashboard sync details and tenant information. The affected functionality involves API endpoints responsible for property listing activation, subscription metadata, and payment link generation.
Recommendations Update to a version newer than 2.0.0.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-62516
GHSA-43CM-Q3MV-2HVJ

Affected Products

Turbotenant