# Security Release for issue #14364

**URL:** https://discuss.tryton.org/t/security-release-for-issue-14364/8952
**Category:** News
**Tags:** security
**Created:** [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14364/8952 "2025-11-21T15:00:48Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [November 21, 2025, 3:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14364/8952/1 "2025-11-21T15:00:48Z")

</div>

[Mahdi Afshar](https://foss.heptapod.net/Mahdi36) has found that [trytond](https://pypi.org/project/trytond/) does not [enforce access rights for the route of the HTML editor](https://bugs.tryton.org/14364) (since version 6.0).

## Impact

[CVSS v3.0 Base Score: 7.1](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:H/RL:O/RC:C)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality: High
- Integrity: Low
- Availability: None

## Workaround

A possible workaround is to block access to the html editor.

## Resolution

All affected users should upgrade `trytond` to the latest version.

Affected versions per series:

- `trytond`:
  - 7.6: \<= 7.6.10
  - 7.4: \<= 7.4.20
  - 7.0: \<= 7.0.39
  - 6.0: \<= 6.0.69

Non affected versions per series:

- `trytond`:
  - 7.6: \>= 7.6.11
  - 7.4: \>= 7.4.21
  - 7.0: \>= 7.0.40
  - 6.0: \>= 6.0.70

## Reference

- [IDOR / Access Control Issue – Unauthorized Access to User Signatures (#14364) · Issues · Tryton / Tryton · GitLab](https://bugs.tryton.org/14364)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![yangoon](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/y/67e7ee/32.png) [@yangoon](https://discuss.tryton.org/u/yangoon)
#### Post date: [December 1, 2025, 9:19pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14364/8952/2 "2025-12-01T21:19:49Z")

</div>

CVE-2025-66423 was assigned to this issue (s.a. [https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=112124](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121242)1)

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [December 21, 2025, 3:01pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14364/8952/3 "2025-12-21T15:01:21Z")

</div>

This topic was automatically closed after 30 days. New replies are no longer allowed.
