---
id: CVE-2025-62527
title: Taguette is an open source qualitative research tool
summary: >-
  Taguette is an open source qualitative research tool. An issue has been
  discovered in Taguette versions prior to 1.5.0. It was possible for an
  attacker to request password reset email containing a malicious link, allowing
  the attacker to…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'
cwe:
  - CWE-15
vendor: taguette
product: taguette
affected:
  - taguette <= 1.5.0
published: '2025-10-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62527'
references:
  - url: >-
      https://github.com/remram44/taguette/security/advisories/GHSA-7rc8-5c8q-jr6j
    label: security-advisories@github.com
  - url: 'https://gitlab.com/remram44/taguette/-/issues/331'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00256
epssPercentile: 0.15781
ingestedAt: '2026-10-08T22:11:53.822Z'
---

## Overview

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim. This issue has been patched in version 1.5.0.

## Affected

- `taguette <= 1.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
