PT-2025-54470 · Titra · Titra

Published

2025-12-31

·

Updated

2026-01-02

·

CVE-2025-69288

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Titra versions prior to 0.99.49
Description Titra is open source project time tracking software. Prior to version 0.99.49, authenticated Admin users can modify the timeEntryRule value in the database. This value is then passed to a NodeVM value to execute as code without sanitization, leading to Remote Code Execution. The timeEntryRule is a vulnerable parameter.
Recommendations Update to version 0.99.49 to address this issue.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-69288
GHSA-PQGX-6WG3-GMVR

Affected Products

Titra