← back
CVE-2025-62527

Taguette vulnerable to password reset link poisoning

CVSS 7.1 HIGHEPSS 0.2%CWE-15
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.2%KEV nãoPoC Patch
Lifecycle
20 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim. This issue has been patched in version 1.5.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Affected products
remram44 · taguette

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →