CVE-2025-62368
CRITICALTaiga <6.8.3 - Code Injection
Title source: llmDescription
Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserialization of untrusted data. This issue is fixed in version 6.9.0.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by rootjog, whotwagner · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/taiga_tribe_gig_unserial.rb
Scores
CVSS v3
9.0
EPSS
0.7078
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
draft
Timeline
Published
Oct 28, 2025
Tracked Since
Feb 18, 2026