
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-70037 is an Open Redirect vulnerability (CWE-601: URL Redirection to Untrusted Site) discovered in Linagora Twake v2023.Q1.1223, an open-source collaboration platform. The flaw allows attackers to redirect users to malicious or untrusted websites, potentially enabling phishing attacks or sensitive information exposure. It was published on March 9, 2026, and affects only the specific version v2023.Q1.1223 of Twake. The CVSS v3.1 base score is 6.1 (Medium) (Red Hat CVE, GitHub Gist).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), where the application fails to properly validate or sanitize user-supplied URL parameters before redirecting users. An unauthenticated, network-based attacker can craft a malicious URL hosted on the Twake instance that, when clicked by a victim, redirects them to an attacker-controlled site. Exploitation requires user interaction (the victim must follow the crafted link), and no authentication or elevated privileges are needed on the part of the attacker. A public disclosure of the vulnerability details was posted by researcher 'zcxlighthouse' on GitHub Gist shortly after the CVE was assigned (GitHub Gist, Red Hat CVE).
Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from the legitimate Twake platform to an attacker-controlled website, facilitating phishing campaigns, credential harvesting, or malware delivery. The confidentiality and integrity impacts are both rated Low, with no direct availability impact, as the vulnerability itself does not grant direct access to server-side data or system resources. However, by leveraging the trusted Twake domain in phishing lures, attackers may more convincingly deceive users into disclosing credentials or other sensitive information (Red Hat CVE, GitHub Gist).
No evidence of active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. A public disclosure (GitHub Gist) describing the vulnerability was created by researcher 'zcxlighthouse' on March 9, 2026, but no weaponized exploit code or exploit kit integration has been identified (GitHub Gist, Red Hat CVE).
?redirect=, ?url=, or similar query parameters) without proper validation.https://twake.example.com/login?redirect=https://attacker.com/phishing.redirect, url, next, or similar query parameters containing external URLs (e.g., ?redirect=https://external-domain.com).The affected repository (Twake v2023.Q1.1223) has been officially deprecated by Linagora, and users are directed to migrate to the successor project, Twake-workplace, which is actively maintained (Twake GitHub). No specific patch for v2023.Q1.1223 has been announced; the primary remediation is to migrate away from the deprecated Twake codebase. As a workaround, administrators should implement server-side URL allowlisting for any redirect parameters, ensuring only trusted internal domains are accepted as redirect destinations.
The vulnerability received limited public attention, with coverage primarily from automated vulnerability tracking services such as VulDB, CVEFeed, and INCIBE-CERT. The original researcher 'zcxlighthouse' published a brief disclosure on GitHub Gist. No significant vendor statements, notable researcher commentary, or broader media coverage has been identified beyond standard CVE aggregation (GitHub Gist).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."