CVE-2025-70037
Received Received - Intake
Open Redirect in linagora Twake Enables Code Execution

Publication date: 2026-03-09

Last updated on: 2026-03-13

Assigner: MITRE

Description
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-09
Last Modified
2026-03-13
Generated
2026-06-16
AI Q&A
2026-03-09
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
linagora twake 2023.q1.1223
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-70037 is a vulnerability found in linagora Twake version v2023.Q1.1223. It is classified under CWE-601, which involves URL Redirection to Untrusted Site.

This vulnerability allows attackers to redirect users to malicious or untrusted websites, potentially leading to phishing attacks or the exposure of sensitive information by deceiving users into visiting harmful sites.

Impact Analysis

This vulnerability can impact you by enabling attackers to redirect you to malicious websites where your sensitive information could be stolen.

It may also allow attackers to execute arbitrary code, which could compromise your system or data security.

Overall, it increases the risk of phishing attacks and unauthorized access to sensitive information.

Compliance Impact

I don't know

Detection Guidance

This vulnerability involves URL redirection to untrusted sites in linagora Twake version v2023.Q1.1223. Detection typically involves identifying if the application redirects users to external or untrusted URLs without proper validation.

Since the vulnerability is related to URL redirection, you can monitor HTTP traffic or logs for suspicious redirect patterns or unexpected external URLs.

Specific commands to detect this vulnerability are not provided in the available resources.

Mitigation Strategies

The vulnerability allows attackers to redirect users to malicious or untrusted websites, potentially leading to phishing or exposure of sensitive information.

Immediate mitigation steps generally include updating linagora Twake to a version where this vulnerability is fixed or applying patches if available.

Additionally, implementing strict validation and sanitization of URLs used in redirection within the application can help prevent exploitation.

No specific mitigation commands or patches are detailed in the provided resources.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-70037. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart