CVE-2025-67502: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-67502 is an Open Redirect vulnerability (CWE-601) in Taguette, a free and open-source qualitative research web application. It affects all versions up to and including 1.5.1 running in multi-user mode, and was patched in version 1.5.2. The vulnerability was published on December 8, 2025, by the project maintainer via GitHub Security Advisory GHSA-5923-r76v-mprm. It carries a CVSS v3.1 base score of 6.1 (Medium) per Feedly/NVD, though the GitHub Advisory Database rates it 5.4 (Moderate) (Github Advisory, Taguette Advisory).

Technical details

The root cause is insufficient validation of the user-controlled next query parameter in two locations within taguette/web/views.py: the _go_to_next() method (called after successful login and when an already-authenticated user visits the login page) and the CookiesPrompt.post() method (called after cookie acceptance). In both cases, the value of next is passed directly to self.redirect() without checking whether it is a relative URL or points to the same host, allowing an attacker to supply an arbitrary external URL (Taguette Advisory). The fix, committed in 67de2d2, introduces an is_next_url_safe() function in taguette/web/base.py that validates the next parameter against a regex anchored to the application's configured BASE_PATH, rejecting absolute URLs, protocol-relative URLs (//evil.com), and path traversal attempts (Patch Commit). Exploitation requires no privileges and only low attack complexity — an attacker simply crafts a URL with a malicious next parameter.

Impact

Successful exploitation enables phishing attacks where victims are silently redirected to attacker-controlled sites after interacting with a legitimate Taguette login or cookie-acceptance page, making credential theft highly convincing. Because the trusted Taguette domain appears in the browser's address bar during the initial interaction, users are more likely to trust a subsequent fake "session expired" prompt and re-enter credentials. Additional consequences include malware distribution via drive-by download pages, session hijacking, and reputational damage to organizations hosting Taguette instances (Taguette Advisory). Availability is not impacted by this vulnerability.

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory itself, demonstrating three trivial attack scenarios requiring only a crafted URL — no authentication or special tooling is needed (Taguette Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.05% (16th percentile), indicating a low near-term exploitation probability (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Taguette instances running in multi-user mode (version ≤ 1.5.1) via internet scanning tools (e.g., Shodan, Censys) or by targeting known organizational deployments.
  2. Craft malicious URL: Construct a URL pointing to the target Taguette instance with the next parameter set to an attacker-controlled phishing site, e.g., https://[taguette-instance]/login?next=https://attacker.com/fake-login.
  3. Deliver via phishing: Send the crafted URL to target users via email, chat, or other social engineering channels, leveraging the trusted Taguette domain to build credibility.
  4. Victim interaction — login redirect: The victim opens the URL, sees the legitimate Taguette login page, and enters valid credentials. Upon successful authentication, Taguette's _go_to_next() method redirects the browser to https://attacker.com/fake-login without validation.
  5. Victim interaction — cookie redirect (alternative): Alternatively, use /cookies?next=https://attacker.com/fake-login; when the victim clicks "Accept cookies," CookiesPrompt.post() redirects them to the attacker's site.
  6. Credential harvesting: The attacker's site presents a convincing "session expired" or re-authentication page to capture credentials, or delivers malware via a drive-by download (Taguette Advisory).

Indicators of compromise

  • Network: HTTP requests to /login or /cookies endpoints containing a next parameter with an absolute external URL (e.g., next=https:// or next=//) in server access logs.
  • Logs: Web server or application logs showing 302/303 redirect responses from /login or /cookies to external domains not matching the Taguette instance's own hostname.
  • Logs: Repeated access to the login page from the same source IP with varying next parameter values, potentially indicating automated URL crafting or testing.
  • User Reports: Users reporting unexpected redirects to unfamiliar sites after logging in or accepting cookies on the Taguette instance (Taguette Advisory).

Mitigation and workarounds

Upgrade Taguette to version 1.5.2 or later, which introduces server-side validation of the next URL parameter to ensure it is a relative path within the application's configured BASE_PATH (Patch Commit, Github Advisory). No official workaround short of upgrading is provided; however, operators unable to upgrade immediately should consider placing a reverse proxy in front of Taguette that strips or validates the next query parameter on requests to /login and /cookies. Additionally, enabling multi-factor authentication and training users to be suspicious of unexpected post-login redirects can reduce the risk of credential theft if exploitation occurs.

Community reactions

The vulnerability was reported by security researcher yueyueL and acknowledged by the Taguette maintainer (remram44), who published the advisory and patch on December 8, 2025 (Taguette Advisory). Red Hat also tracked the CVE in their security database (Red Hat CVE). No significant broader media coverage or notable community debate has been identified beyond standard CVE aggregator publications.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management