# \#security

**URL:** https://discuss.tryton.org/tag/security/51.md

[Latest](https://discuss.tryton.org/latest.md) · [Categories](https://discuss.tryton.org/categories.md) · [Tags](https://discuss.tryton.org/tags.md)

---

## [Security Release for issue #5160 and #14869](https://discuss.tryton.org/t/security-release-for-issue-5160-and-14869/9266)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 2\
**Last updated:** [July 3, 2026, 11:13am UTC](https://discuss.tryton.org/t/security-release-for-issue-5160-and-14869/9266 "2026-07-03T11:13:53Z")

</div>

The user titou has discovered that the administrator group can execute Python code on the server which is hidden inside an uploaded report template. And Dan Shallom has discovered that the same can also be accomplished…

---

## [Security Release for issue 14907](https://discuss.tryton.org/t/security-release-for-issue-14907/9267)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [July 3, 2026, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14907/9267 "2026-07-03T06:00:50Z")

</div>

Cédric Krier has discovered that access is not enforced when browsing record instances in template. Impact CVSS v3.0 Base Score: 6.5 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Interact…

---

## [Security Release for issue #14363](https://discuss.tryton.org/t/security-release-for-issue-14363/8951)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [December 1, 2025, 9:24pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14363/8951 "2025-12-01T21:24:42Z")

</div>

Abdulfatah Abdillahi has found that sao does not escape the completion values. The content of completion is generally the record name which may be edited in many ways depending on the model. The content may include some …

---

## [Security Release for issue #14366](https://discuss.tryton.org/t/security-release-for-issue-14366/8953)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [December 1, 2025, 9:21pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14366/8953 "2025-12-01T21:21:57Z")

</div>

Cédric Krier has found that trytond does not enforce access rights for data export (since version 6.0). Impact CVSS v3.0 Base Score: 6.5 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User Inte…

---

## [Security Release for issue #14364](https://discuss.tryton.org/t/security-release-for-issue-14364/8952)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [December 1, 2025, 9:19pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14364/8952 "2025-12-01T21:19:49Z")

</div>

Mahdi Afshar has found that trytond does not enforce access rights for the route of the HTML editor (since version 6.0). Impact CVSS v3.0 Base Score: 7.1 Attack Vector: Network Attack Complexity: Low Privileges Requir…

---

## [Security Release for issue #14354](https://discuss.tryton.org/t/security-release-for-issue-14354/8950)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 2\
**Last updated:** [December 1, 2025, 9:16pm UTC](https://discuss.tryton.org/t/security-release-for-issue-14354/8950 "2025-12-01T21:16:22Z")

</div>

Mahdi Afshar and Abdulfatah Abdillahi have found that trytond sends the trace-back to the clients for unexpected errors. This trace-back may leak information about the server setup. Impact CVSS v3.0 Base Score: 4.3 At…

---

## [Security Release for issue #14220](https://discuss.tryton.org/t/security-release-for-issue-14220/8823)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [September 15, 2025, 7:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14220/8823 "2025-09-15T07:00:00Z")

</div>

Luis Falcon has found that trytond may log sensitive data like passwords when the logging level is set to INFO. Impact CVSS v3.0 Base Score: 4.2 Attack Vector: Network Attack Complexity: Low Privileges Required: High U…

---

## [Security Release for issue #14290](https://discuss.tryton.org/t/security-release-for-issue-14290/8895)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [October 21, 2025, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-14290/8895 "2025-10-21T06:00:02Z")

</div>

Brandon Da Costa and Mahdi Afshar have found that sao executes JavaScript included in HTML documents (such as attachments). These documents may be uploaded by any authenticated user. The JavaScript is executed in the sam…

---

## [Security Release for issue #93](https://discuss.tryton.org/t/security-release-for-issue-93/7889)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 2:19pm UTC](https://discuss.tryton.org/t/security-release-for-issue-93/7889 "2024-10-10T14:19:02Z")

</div>

Cédric Krier has found that python-sql does not escape non-Expression for unary operators (like And and Or) which makes any system exposing those vulnerable to an SQL injection attack. Impact CVSS v3.0 Base Score: 9.1 …

---

## [Security Release for issues #13505 and #13506](https://discuss.tryton.org/t/security-release-for-issues-13505-and-13506/7846)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [September 17, 2024, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issues-13505-and-13506/7846 "2024-09-17T06:00:29Z")

</div>

Albert Cervera has found that trytond allows to execute reports for records that user has no read access and also for reports limited to a set of group that the user is not. Impact CVSS v3.0 Base Score: 4.3 Attack Vec…

---

## [Security Release for issue #92](https://discuss.tryton.org/t/security-release-for-issue-92/7330)

<div class="topic-metadata">

**Author:** [@nicoe](https://discuss.tryton.org/u/nicoe)\
**Replies:** 0\
**Last updated:** [June 10, 2024, 8:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-92/7330 "2024-06-10T08:00:14Z")

</div>

Ashish Kunwar has found that python-sql accepts any string in the offset or limit parameters when python is ran with -O which makes any system exposing those vulnerable to an SQL injection attack. Impact CVSS v3.0 Base …

---

## [Security Release for issue #13142](https://discuss.tryton.org/t/security-release-for-issue-13142/7196)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 4:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-13142/7196 "2024-04-17T16:00:16Z")

</div>

Cédric Krier has found that trytond accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks. Impact CVSS v3.0 Base Score: 5.3 Attack Vector: Network Attack Complexity: Lo…

---

## [Security Release for issue #12428](https://discuss.tryton.org/t/security-release-for-issue-12428/6397)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 4:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue-12428/6397 "2023-07-31T16:00:15Z")

</div>

Synopsis Edbo and Cédric Krier have found that record rules are not enforced by trytond when only reading fields without an SQL type (like Function fields). Impact CVSS v3.0 Base Score: 6.5 Attack Vector: Network Atta…

---

## [Security release for issue12108](https://discuss.tryton.org/t/security-release-for-issue12108/5999)

<div class="topic-metadata">

**Author:** [@pokoli](https://discuss.tryton.org/u/pokoli)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 7:00am UTC](https://discuss.tryton.org/t/security-release-for-issue12108/5999 "2023-03-07T07:00:45Z")

</div>

Synopsis A vulnerability in trytond has been found by José Antonio Díaz Miralles (@tiyujopite). Due to issue12108, the Tryton server does not refresh the authenticated user data but instead uses the values from the fir…

---

## [Security Release for issue11219 and issue11244](https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [March 9, 2022, 8:41am UTC](https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059 "2022-03-09T08:41:57Z")

</div>

Synopsis XML parsing vulnerabilities have been found by Jeremy Mousset in trytond and some modules. With issue11219 an authenticated user can make the server to parse a crafted XML SEPA file to access arbitrary files on…

---

## [Security Release for issue10068](https://discuss.tryton.org/t/security-release-for-issue10068/3803)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [February 12, 2021, 9:30am UTC](https://discuss.tryton.org/t/security-release-for-issue10068/3803 "2021-02-12T09:30:05Z")

</div>

Synopsis A vulnerability in trytond has been found by German Dario Alvarez. With issue10068, the WSGI server does not prevent serving files outside the root directory. This allows an attacker to retrieve the content of …

---

## [Security Release for issue9453](https://discuss.tryton.org/t/security-release-for-issue9453/3005)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [July 10, 2020, 8:05am UTC](https://discuss.tryton.org/t/security-release-for-issue9453/3005 "2020-07-10T08:05:04Z")

</div>

Synopsis A vulnerability in sao has been found by Cédric Krier. With issue 9453, the web client does not escape the HTML tags from user data in translated richtext widgets. This allows cross-site scripting attacks which…

---

## [Security Release for issue9394](https://discuss.tryton.org/t/security-release-for-issue9394/2947)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 4:30pm UTC](https://discuss.tryton.org/t/security-release-for-issue9394/2947 "2020-06-29T16:30:01Z")

</div>

Synopsis A vulnerability in sao has been found by Cédric Krier. With issue9394, the web client does not escape the HTML tags from user data. This allows cross-site scripting attacks which can result in session hijacking…

---

## [Security Release for issue9405](https://discuss.tryton.org/t/security-release-for-issue9405/2948)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [June 29, 2020, 4:30pm UTC](https://discuss.tryton.org/t/security-release-for-issue9405/2948 "2020-06-29T16:30:01Z")

</div>

Synopsis A vulnerability in sao has been found by Coopengo and solved by Nicolas Évrard. With issue 9405, the web client does not escape the HTML tags from user data in richtext widgets. This allows cross-site scripting …

---

## [Security Release for issue9351](https://discuss.tryton.org/t/security-release-for-issue9351/2772)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [May 26, 2020, 8:30am UTC](https://discuss.tryton.org/t/security-release-for-issue9351/2772 "2020-05-26T08:30:00Z")

</div>

Synopsis A vulnerability in sao has been found by Benjamin Kunz Mejri at Vulnerability-Lab. But they publish it without using our responsive disclosure procedure so we had to make this fix in the hurry. With issue9351 ,…

---

## [Security Release for issue9108](https://discuss.tryton.org/t/security-release-for-issue9108/2431)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [March 10, 2020, 5:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue9108/2431 "2020-03-10T17:00:07Z")

</div>

Synopsis A vulnerability in trytond has been found by Maxime Richez. With issue9108, the trytond server does not enforce access right on wizard relying on the access right of the model on which it runs. So an authentic…

---

## [Security Release for issue9089](https://discuss.tryton.org/t/security-release-for-issue9089/2430)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [March 10, 2020, 5:00pm UTC](https://discuss.tryton.org/t/security-release-for-issue9089/2430 "2020-03-10T17:00:07Z")

</div>

Synopsis A vulnerability in sao has been found by Cédric Krier . With issue9089, the web client does not set noreferrer nor noopener to open external links. An attacker could trick a Tryton user to open a crafted URL …

---

## [Security Release for issue8189](https://discuss.tryton.org/t/security-release-for-issue8189/1262)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 8:47am UTC](https://discuss.tryton.org/t/security-release-for-issue8189/1262 "2019-04-05T08:47:39Z")

</div>

Synopsis A vulnerability in tryton has been found by Cédric Krier. With issue8189, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values. Imp…

---

## [Security Release for issue7792](https://discuss.tryton.org/t/security-release-for-issue7792/830)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 1\
**Last updated:** [November 23, 2018, 12:41pm UTC](https://discuss.tryton.org/t/security-release-for-issue7792/830 "2018-11-23T12:41:56Z")

</div>

Synopsis A vulnerability in tryton has been found by Cédric Krier. With issue7792 the client tries to make the connection to the bus in plain text instead of encrypted. The connection tentative fails, but it contains in…

---

## [Security Release for issue7766](https://discuss.tryton.org/t/security-release-for-issue7766/861)

<div class="topic-metadata">

**Author:** [@ced](https://discuss.tryton.org/u/ced)\
**Replies:** 0\
**Last updated:** [November 12, 2018, 10:25pm UTC](https://discuss.tryton.org/t/security-release-for-issue7766/861 "2018-11-12T22:25:00Z")

</div>

Synopsis A vulnerability in trytond, the core package of Tryton, has been found by Cédric Krier. The issue7766 shows that it is possible for an authenticated user to guess the value of a field for which he has no access…
