# Security Release for issue #14354

**URL:** https://discuss.tryton.org/t/security-release-for-issue-14354/8950
**Category:** News
**Tags:** security
**Created:** [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950 "2025-11-21T15:00:48Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950/1 "2025-11-21T15:00:48Z")

</div>

[Mahdi Afshar](https://foss.heptapod.net/Mahdi36) and [Abdulfatah Abdillahi](https://foss.heptapod.net/Abdul123) have found that [trytond](https://pypi.org/project/trytond/) [sends the trace-back to the clients for unexpected errors](https://bugs.tryton.org/14354). This trace-back may [leak information about the server setup](https://bugs.tryton.org/14355).

## Impact

[CVSS v3.0 Base Score: 4.3](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality: Low
- Integrity: None
- Availability: None

## Workaround

A possible workaround is to configure an error handler which would remove the trace-back from the response.

## Resolution

All affected users should upgrade `trytond` to the latest version.

Affected versions per series:

- `trytond`:
  - 7.6: \<= 7.6.10
  - 7.4: \<= 7.4.20
  - 7.0: \<= 7.0.39
  - 6.0: \<= 6.0.69

Non affected versions per series:

- `trytond`:
  - 7.6: \>= 7.6.11
  - 7.4: \>= 7.4.21
  - 7.0: \>= 7.0.40
  - 6.0: \>= 6.0.70

## Reference

- [Information disclosure: unhandled KeyError returns full Python stack trace for unknown fields in JSON-RPC (model.party.party.create) (#14354) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/14354)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![udono](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/udono/32/2114_2.png) [@udono](https://discuss.tryton.org/u/udono)
#### Post date: [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950/2 "2025-11-21T15:00:48Z")

</div>

Why not also add [Information Disclosure via Stack Trace in JSON-RPC API (#14355) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/14355) as reference?

---

<div class="post-metadata">

### Author: ![yangoon](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/y/67e7ee/32.png) [@yangoon](https://discuss.tryton.org/u/yangoon)
#### Post date: [December 1, 2025, 9:16pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950/3 "2025-12-01T21:16:22Z")

</div>

CVE-2025-66422 was assigned to this issue (s.a. [https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121242](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121242))

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [December 21, 2025, 3:01pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950/4 "2025-12-21T15:01:22Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
