CVE-2025-67502
Last modified
CVE-2025-67502 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP redirects without any validation. This can be exploited for phishing attacks where victims believe they are interacting with a trusted Taguette instance but are redirected to a malicious site designed to steal credentials or deliver malware. This issue is fixed in version 1.5.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Taguette | Taguette | < 1.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67502?
How severe is CVE-2025-67502?
How do I fix CVE-2025-67502?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67497Rejected reason: Further research determined the issue is no…
- CVE-2025-67498Rejected reason: Further research determined the issue is no…
- CVE-2025-67499The CNI portmap plugin allows containers to emulate opening …3.6
- CVE-2025-6750A vulnerability, which was classified as problematic, has be…3.3
- CVE-2025-67500Mastodon is a free, open-source social network server based …3.7
- CVE-2025-67501WeGIA is an open source Web Manager for Institutions with a …8.8
- CVE-2025-67503Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2025-67504WBCE CMS is a content management system. Versions 1.6.4 and …9.8
- CVE-2025-67505Okta Java Management SDK facilitates interactions with the O…8.4
- CVE-2025-67506PipesHub is a fully extensible workplace AI platform for ent…9.8
- CVE-2025-67507Filament is a collection of full-stack components for accele…8.1
- CVE-2025-67508gardenctl is a command-line client for the Gardener which co…8.4
Are you affected by CVE-2025-67502?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
