CVE-2025-14692: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-14692 is an open redirect vulnerability (CWE-601) in Mayan EDMS, an open-source document management system. The flaw exists in the /authentication/ endpoint and allows unauthenticated remote attackers to redirect users to arbitrary external websites by manipulating URL fragment or next parameters. It affects Mayan EDMS versions prior to 4.10.2 (specifically: < 4.6.12, >= 4.7.0 < 4.7.8, >= 4.8.0 < 4.8.10, >= 4.9.0 < 4.9.7, and >= 4.10.0 < 4.10.2). The vulnerability was published on December 14–15, 2025, with a CVSS v3.1 base score of 6.1 (Medium) per NVD and a CVSS v4.0 score of 2.1 (Low) per the CNA (GitHub Advisory, NVD).

Technical details

The root cause is insecure client-side JavaScript handling of the URL hash fragment (window.location.hash) within Mayan EDMS's navigation template (CWE-601). The vulnerable code constructs a redirect URL by appending window.location.pathname and window.location.search to the hash fragment without any sanitization or validation, then assigns the result directly to window.location. Multiple authentication-related endpoints are affected, including /authentication/login/, /authentication/password/reset/, and their variants with next parameters. An attacker can craft a URL such as http://target/authentication/login/#https://evil.com to trigger an automatic redirect to an attacker-controlled site upon page load, requiring no authentication (GitHub PoC, GitHub Advisory).

Impact

Successful exploitation enables phishing attacks by silently redirecting users visiting legitimate Mayan EDMS authentication pages to attacker-controlled sites such as credential harvesting pages or malware distribution portals. The vulnerability has no direct impact on availability or server-side confidentiality, but poses a meaningful integrity and social engineering risk — particularly for organizations where users trust the EDMS domain. Lateral movement is not directly facilitated, but stolen credentials obtained via phishing could enable subsequent unauthorized access to the document management system and its stored content (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept exploit is available on GitHub, published by researcher ionutluca888, demonstrating the open redirect across multiple authentication endpoints (GitHub PoC). The vulnerability requires no authentication and only passive user interaction (a victim clicking a crafted link), making it straightforward to weaponize for phishing campaigns. The EPSS score is approximately 0.085–0.097%, indicating a low but non-negligible probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Mayan EDMS instances running versions prior to 4.10.2 using search engines, Shodan, or Censys by fingerprinting the application's login page at /authentication/login/.
  2. Craft malicious URL: Construct a redirect URL targeting the vulnerable hash fragment, e.g., http://<target>/authentication/login/#https://evil.com or with a next parameter variant such as http://<target>/authentication/login/?next=/home/#https://evil.com.
  3. Deliver the link: Send the crafted URL to target users via phishing email, social media message, or embedded in other content, leveraging the trusted Mayan EDMS domain to increase click-through likelihood.
  4. Victim interaction: When the victim opens the link, the vulnerable client-side JavaScript in the navigation template reads window.location.hash (attacker-controlled) and assigns it to window.location, immediately redirecting the browser to the attacker's site without any warning.
  5. Harvest credentials or deliver payload: The victim lands on the attacker-controlled page (e.g., a cloned Mayan EDMS login page), where credentials can be harvested or malware delivered (GitHub PoC).

Indicators of compromise

  • Network: HTTP requests to /authentication/login/, /authentication/password/reset/, or their ?next= variants containing a URL fragment (#) with an external domain (e.g., #https://evil.com); outbound redirects (HTTP 3xx or JavaScript-based) from the Mayan EDMS server to unexpected external domains.
  • Logs: Web server access logs showing GET requests to authentication endpoints with encoded or raw external URLs in the fragment or next parameter; repeated access from diverse source IPs to authentication endpoints with suspicious hash values.
  • User Reports: End users reporting unexpected redirects to unfamiliar websites after clicking Mayan EDMS links, particularly login or password reset links received via email.

Mitigation and workarounds

The vendor has released patched versions addressing this vulnerability across all supported branches: 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12. Upgrading to the appropriate patched version is the recommended remediation. The vendor confirmed the fix in version 4.10.2 and indicated that backports for older versions were in progress via their CI pipelines. No configuration-based workaround is documented; upgrading is the only reliable mitigation. Organizations should also educate users about phishing risks associated with authentication redirect links (GitHub Advisory, Mayan Release Notes).

Community reactions

The vulnerability received limited but notable coverage, including a post on Bluesky via the CVE tracking account and coverage by security aggregators such as Vulners, CIRCL, and INCIBE-CERT. The infinitsec.net blog published a dedicated write-up on the vulnerability shortly after disclosure. No major vendor statements beyond the Mayan EDMS release notes have been identified, and community reaction has been modest given the medium/low severity rating.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management