CVE-2025-47292

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47292
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47292.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47292
Aliases
  • GHSA-hf7r-rjh4-5fc8
Published
2025-05-14T11:16:31Z
Modified
2025-05-17T14:29:18.125062Z
Summary
[none]
Details

Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the DebateAlternateArgumentsResolver deserializes a Cursor, allowing any classes and which can be controlled by unauthenticated user. Exploitation of this vulnerability can lead to Remote Code Execution. The vulnerability is fixed in commit 812f2a7d271b76deab1175bdaf2be0b8102dd198.

References

Affected packages

Git / github.com/cap-collectif/cap-collectif

Affected ranges

Type
GIT
Repo
https://github.com/cap-collectif/cap-collectif
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed