GHSA-7rc8-5c8q-jr6jHighCVSS 7.1

Taguette password reset link poisoning

Published
October 20, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim.

Patches

Users should upgrade to Taguette 1.5.0.

References

  • https://gitlab.com/remram44/taguette/-/issues/331

🎯 Affected products1

  • pip/taguette:< 1.5.0

🔗 References (5)