
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67502 is an Open Redirect vulnerability (CWE-601) in Taguette, a free and open-source qualitative research web application. It affects all versions up to and including 1.5.1 running in multi-user mode, and was patched in version 1.5.2. The vulnerability was published on December 8, 2025, by the project maintainer via GitHub Security Advisory GHSA-5923-r76v-mprm. It carries a CVSS v3.1 base score of 6.1 (Medium) per Feedly/NVD, though the GitHub Advisory Database rates it 5.4 (Moderate) (Github Advisory, Taguette Advisory).
The root cause is insufficient validation of the user-controlled next query parameter in two locations within taguette/web/views.py: the _go_to_next() method (called after successful login and when an already-authenticated user visits the login page) and the CookiesPrompt.post() method (called after cookie acceptance). In both cases, the value of next is passed directly to self.redirect() without checking whether it is a relative URL or points to the same host, allowing an attacker to supply an arbitrary external URL (Taguette Advisory). The fix, committed in 67de2d2, introduces an is_next_url_safe() function in taguette/web/base.py that validates the next parameter against a regex anchored to the application's configured BASE_PATH, rejecting absolute URLs, protocol-relative URLs (//evil.com), and path traversal attempts (Patch Commit). Exploitation requires no privileges and only low attack complexity — an attacker simply crafts a URL with a malicious next parameter.
Successful exploitation enables phishing attacks where victims are silently redirected to attacker-controlled sites after interacting with a legitimate Taguette login or cookie-acceptance page, making credential theft highly convincing. Because the trusted Taguette domain appears in the browser's address bar during the initial interaction, users are more likely to trust a subsequent fake "session expired" prompt and re-enter credentials. Additional consequences include malware distribution via drive-by download pages, session hijacking, and reputational damage to organizations hosting Taguette instances (Taguette Advisory). Availability is not impacted by this vulnerability.
A proof-of-concept is publicly documented in the GitHub Security Advisory itself, demonstrating three trivial attack scenarios requiring only a crafted URL — no authentication or special tooling is needed (Taguette Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.05% (16th percentile), indicating a low near-term exploitation probability (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
next parameter set to an attacker-controlled phishing site, e.g., https://[taguette-instance]/login?next=https://attacker.com/fake-login._go_to_next() method redirects the browser to https://attacker.com/fake-login without validation./cookies?next=https://attacker.com/fake-login; when the victim clicks "Accept cookies," CookiesPrompt.post() redirects them to the attacker's site./login or /cookies endpoints containing a next parameter with an absolute external URL (e.g., next=https:// or next=//) in server access logs./login or /cookies to external domains not matching the Taguette instance's own hostname.next parameter values, potentially indicating automated URL crafting or testing.Upgrade Taguette to version 1.5.2 or later, which introduces server-side validation of the next URL parameter to ensure it is a relative path within the application's configured BASE_PATH (Patch Commit, Github Advisory). No official workaround short of upgrading is provided; however, operators unable to upgrade immediately should consider placing a reverse proxy in front of Taguette that strips or validates the next query parameter on requests to /login and /cookies. Additionally, enabling multi-factor authentication and training users to be suspicious of unexpected post-login redirects can reduce the risk of credential theft if exploitation occurs.
The vulnerability was reported by security researcher yueyueL and acknowledged by the Taguette maintainer (remram44), who published the advisory and patch on December 8, 2025 (Taguette Advisory). Red Hat also tracked the CVE in their security database (Red Hat CVE). No significant broader media coverage or notable community debate has been identified beyond standard CVE aggregator publications.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."