Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass intended restrictions allowing unauthorized access and changes despite role-based controls. Since it requires privileged access initially, exploitation is restricted to malicious insiders or compromised group managers accounts. Version 1.2.0 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/galette/galette/security/advisories/GHSA-gp9g-gf56-fcxx | Exploit Vendor Advisory |
Configurations
History
05 Jan 2026, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/galette/galette/security/advisories/GHSA-gp9g-gf56-fcxx - Exploit, Vendor Advisory | |
| First Time |
Galette
Galette galette |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| CPE | cpe:2.3:a:galette:galette:*:*:*:*:*:*:*:* |
19 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-19 17:15
Updated : 2026-01-05 18:03
NVD link : CVE-2025-58052
Mitre link : CVE-2025-58052
CVE.ORG link : CVE-2025-58052
JSON object : View
Products Affected
galette
- galette
CWE
CWE-863
Incorrect Authorization
