PT-2025-50295 · Taguette · Taguette

CVE-2025-67502

·

Published

2025-12-09

·

Updated

2026-07-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Taguette versions prior to 1.5.2
Description Taguette is a qualitative research tool susceptible to an open redirect issue. Attackers can create malicious URLs that redirect authenticated users to arbitrary external websites. The application utilizes a user-controlled next parameter in HTTP redirects without proper validation, enabling potential phishing attacks. Victims may be deceived into believing they are interacting with a legitimate Taguette instance while being redirected to a malicious site designed to steal credentials or deliver malware.
Recommendations Update to Taguette version 1.5.2 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67502
GHSA-5923-R76V-MPRM
PYSEC-2026-1948

Affected Products

Taguette