CVE-2025-62528
MEDIUMTaguette < 1.5.0 - Stored Cross-Site Scripting via Project Name or Description
Title source: llmDescription
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in name or description fields which would run on project load. This issue has been patched in version 1.5.0.
References (2)
Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://github.com/remram44/taguette/security/advisories/GHSA-g9qw-g6rv-3889
Issue Tracking, Vendor Advisory x_refsource_misc
https://gitlab.com/remram44/taguette/-/issues/330
Scores
CVSS v3
5.4
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
pypi/taguette
0 - 1.5.0PyPI
taguette/taguette
< 1.5.0
Published
Oct 20, 2025
Tracked Since
Feb 18, 2026