CVE-2025-62368
CRITICALTaiga <6.8.3 - Code Injection
Title source: llmDescription
Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserialization of untrusted data. This issue is fixed in version 6.9.0.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by rootjog, whotwagner · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/taiga_tribe_gig_unserial.rb
Scores
CVSS v3
9.0
EPSS
0.6408
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-502
Status
published
Products (1)
taigaio/taiga-back
< 6.9.0
Published
Oct 28, 2025
Tracked Since
Feb 18, 2026