CVE-2025-62368

CRITICAL

Taiga <6.8.3 - Code Injection

Title source: llm

Description

Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserialization of untrusted data. This issue is fixed in version 6.9.0.

Exploits (1)

metasploit WORKING POC EXCELLENT
by rootjog, whotwagner · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/taiga_tribe_gig_unserial.rb

Scores

CVSS v3 9.0
EPSS 0.7078
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-502
Status draft

Timeline

Published Oct 28, 2025
Tracked Since Feb 18, 2026