CVE-2025-62528 Overview
CVE-2025-62528 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in Taguette, an open source qualitative research tool. The flaw affects Taguette versions prior to 1.5.0. Authenticated project members can inject JavaScript into project name or description fields. The injected script executes in the browser of any user who loads the affected project. This creates a vector for session theft, credential harvesting, and actions performed under another user's context. The maintainer patched the issue in version 1.5.0.
Critical Impact
Any project member can plant persistent JavaScript that runs in collaborators' browsers on project load, enabling account takeover within shared research workspaces.
Affected Products
- Taguette versions prior to 1.5.0
- Self-hosted Taguette server deployments
- Multi-user Taguette collaborative research projects
Discovery Timeline
- 2025-10-20 - CVE-2025-62528 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-62528
Vulnerability Analysis
The vulnerability is a stored XSS issue in the project metadata handling logic. Taguette accepts user-supplied text in the project name and description fields without adequately sanitizing or encoding HTML entities before rendering. When another user loads the project, the browser parses the stored content as HTML and executes any embedded <script> tags or event-handler attributes.
Because the payload is stored server-side and delivered to every user who opens the project, exploitation does not require the attacker to be present. Any collaborator visiting the project triggers the payload under their own session context.
Root Cause
The root cause is missing output encoding for project metadata fields in the templating or DOM-rendering path. User input intended as plain text is inserted into HTML contexts without escaping characters such as <, >, and ". This matches the classic pattern described in CWE-79 (Improper Neutralization of Input During Web Page Generation).
Attack Vector
Exploitation requires an authenticated account with membership in a shared project. The attacker edits the project name or description and stores a JavaScript payload such as a <script> tag or an event handler on an inline element. When any other project member loads the project, the payload executes in their browser session. The attacker can then read authenticated session cookies, invoke API endpoints as the victim, or modify project data. Refer to the GitHub Security Advisory GHSA-g9qw-g6rv-3889 for advisory details.
Detection Methods for CVE-2025-62528
Indicators of Compromise
- Project name or description fields containing HTML tags, <script> elements, or on* event-handler attributes.
- Unexpected outbound HTTP requests from user browsers immediately after opening a Taguette project.
- Session or credential anomalies affecting users who recently accessed a shared project.
Detection Strategies
- Query the Taguette database for project metadata containing characters such as <, >, or the substring javascript:.
- Review web server access logs for POST or PATCH requests to project-update endpoints containing HTML markup in payloads.
- Deploy a Content Security Policy (CSP) in report-only mode to surface inline-script violations originating from Taguette pages.
Monitoring Recommendations
- Track project edit events and alert on metadata mutations that include HTML-control characters.
- Correlate browser error telemetry with Taguette page loads to identify script injection attempts.
- Monitor authentication logs for concurrent sessions or unusual API activity from users who loaded a suspect project.
How to Mitigate CVE-2025-62528
Immediate Actions Required
- Upgrade all Taguette instances to version 1.5.0 or later without delay.
- Audit existing project name and description fields for stored HTML or script payloads and remove them.
- Rotate session tokens and force re-authentication for users who accessed potentially affected projects.
- Restrict project membership to trusted collaborators until the upgrade is verified.
Patch Information
The issue is fixed in Taguette 1.5.0. See the GitHub Security Advisory GHSA-g9qw-g6rv-3889 and the corresponding GitLab Issue #330 for maintainer notes and the patched release.
Workarounds
- If immediate patching is not possible, restrict project membership to a small, trusted group and disable open registration.
- Deploy a strict Content Security Policy that blocks inline scripts on the Taguette host to reduce payload execution.
- Place Taguette behind a Web Application Firewall (WAF) rule that inspects project-metadata endpoints for HTML markup.
# Upgrade Taguette to the patched release
pip install --upgrade 'taguette>=1.5.0'
# Verify installed version
taguette --version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
