CVE-2025-70037
Homebrew vulnerability analysis and mitigation

Overview

CVE-2025-70037 is an Open Redirect vulnerability (CWE-601: URL Redirection to Untrusted Site) discovered in Linagora Twake v2023.Q1.1223, an open-source collaboration platform. The flaw allows attackers to redirect users to malicious or untrusted websites, potentially enabling phishing attacks or sensitive information exposure. It was published on March 9, 2026, and affects only the specific version v2023.Q1.1223 of Twake. The CVSS v3.1 base score is 6.1 (Medium) (Red Hat CVE, GitHub Gist).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), where the application fails to properly validate or sanitize user-supplied URL parameters before redirecting users. An unauthenticated, network-based attacker can craft a malicious URL hosted on the Twake instance that, when clicked by a victim, redirects them to an attacker-controlled site. Exploitation requires user interaction (the victim must follow the crafted link), and no authentication or elevated privileges are needed on the part of the attacker. A public disclosure of the vulnerability details was posted by researcher 'zcxlighthouse' on GitHub Gist shortly after the CVE was assigned (GitHub Gist, Red Hat CVE).

Impact

Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from the legitimate Twake platform to an attacker-controlled website, facilitating phishing campaigns, credential harvesting, or malware delivery. The confidentiality and integrity impacts are both rated Low, with no direct availability impact, as the vulnerability itself does not grant direct access to server-side data or system resources. However, by leveraging the trusted Twake domain in phishing lures, attackers may more convincingly deceive users into disclosing credentials or other sensitive information (Red Hat CVE, GitHub Gist).

Exploitability

No evidence of active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. A public disclosure (GitHub Gist) describing the vulnerability was created by researcher 'zcxlighthouse' on March 9, 2026, but no weaponized exploit code or exploit kit integration has been identified (GitHub Gist, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Twake instances running version v2023.Q1.1223 using search engines or web scanning tools.
  2. Identify redirect parameter: Locate URL parameters within the Twake application that accept redirect destinations (e.g., ?redirect=, ?url=, or similar query parameters) without proper validation.
  3. Craft malicious URL: Construct a URL pointing to the legitimate Twake domain but embedding an attacker-controlled destination, such as https://twake.example.com/login?redirect=https://attacker.com/phishing.
  4. Deliver to victim: Send the crafted URL to target users via email, chat, or other social engineering channels, leveraging the trusted Twake domain to increase credibility.
  5. Harvest credentials or deliver malware: When the victim clicks the link and is redirected to the attacker's site, capture credentials via a phishing page or deliver malicious payloads (GitHub Gist).

Indicators of compromise

  • Network: Outbound HTTP redirects (301/302 responses) from the Twake server to external, non-whitelisted domains in web server access logs.
  • Logs: Web server or application logs showing requests to Twake endpoints with suspicious redirect, url, next, or similar query parameters containing external URLs (e.g., ?redirect=https://external-domain.com).
  • User Reports: End-user reports of being unexpectedly redirected to unfamiliar or suspicious websites after clicking Twake links.

Mitigation and workarounds

The affected repository (Twake v2023.Q1.1223) has been officially deprecated by Linagora, and users are directed to migrate to the successor project, Twake-workplace, which is actively maintained (Twake GitHub). No specific patch for v2023.Q1.1223 has been announced; the primary remediation is to migrate away from the deprecated Twake codebase. As a workaround, administrators should implement server-side URL allowlisting for any redirect parameters, ensuring only trusted internal domains are accepted as redirect destinations.

Community reactions

The vulnerability received limited public attention, with coverage primarily from automated vulnerability tracking services such as VulDB, CVEFeed, and INCIBE-CERT. The original researcher 'zcxlighthouse' published a brief disclosure on GitHub Gist. No significant vendor statements, notable researcher commentary, or broader media coverage has been identified beyond standard CVE aggregation (GitHub Gist).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management