CVE-2025-67502
MEDIUMTaguette < 1.5.2 - Open Redirect via Unvalidated Next Parameter
Title source: llmDescription
Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after authentication. The application accepts a user-controlled next parameter and uses it directly in HTTP redirects without any validation. This can be exploited for phishing attacks where victims believe they are interacting with a trusted Taguette instance but are redirected to a malicious site designed to steal credentials or deliver malware. This issue is fixed in version 1.5.2.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/remram44/taguette/security/advisories/GHSA-5923-r76v-mprm
Scores
CVSS v3
5.4
EPSS
0.0023
EPSS Percentile
13.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (2)
pypi/taguette
0 - 1.5.2PyPI
taguette/taguette
< 1.5.2
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026