affected: - package: ecosystem: PyPI name: taguette purl: pkg:pypi/taguette ranges: - events: - introduced: '0' - fixed: 1.5.0 type: ECOSYSTEM versions: - '0.0' - 0.0.1 - '0.1' - '0.10' - 0.10.1 - '0.11' - '0.2' - '0.3' - '0.4' - 0.4.1 - 0.4.2 - 0.4.3 - 0.4.4 - 0.5.post1 - '0.6' - '0.7' - '0.8' - '0.9' - 0.9.1 - 0.9.2 - 1.0.0 - 1.0.1 - 1.1.0 - 1.1.1 - 1.2.0 - 1.3.0 - 1.4.1 aliases: - CVE-2025-62528 - GHSA-g9qw-g6rv-3889 details: Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in name or description fields which would run on project load. This issue has been patched in version 1.5.0. id: PYSEC-2025-188 modified: '2026-05-20T09:19:18.148594Z' published: '2025-10-20T20:15:37.723Z' references: - type: REPORT url: https://github.com/remram44/taguette/security/advisories/GHSA-g9qw-g6rv-3889 - type: REPORT url: https://gitlab.com/remram44/taguette/-/issues/330 severity: - score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N type: CVSS_V3