Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e | Patch |
| https://github.com/kromitgmbh/titra/releases/tag/0.99.49 | Release Notes |
| https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr | Exploit Mitigation Vendor Advisory |
| https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr | Exploit Mitigation Vendor Advisory |
Configurations
History
17 Jun 2026, 10:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr - Exploit, Mitigation, Vendor Advisory | |
| Summary |
|
13 Jan 2026, 15:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e - Patch | |
| References | () https://github.com/kromitgmbh/titra/releases/tag/0.99.49 - Release Notes | |
| References | () https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr - Exploit, Vendor Advisory, Mitigation | |
| First Time |
Kromit titra
Kromit |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:kromit:titra:*:*:*:*:*:*:*:* |
02 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr - |
31 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-31 22:15
Updated : 2026-06-17 10:00
NVD link : CVE-2025-69288
Mitre link : CVE-2025-69288
CVE.ORG link : CVE-2025-69288
JSON object : View
Products Affected
kromit
- titra
CWE
