Junglewise Threat Intelligence

CVE-2025-14692: Mayan EDMS open redirect in authentication component

CVE-2025-14692 · Severity: medium · CVSS 4.3 · Published 2025-12-15

Technologies: mayan-edms (PyPI). Vendors: PyPI.

Executive brief

Mayan EDMS, an open-source document management system, is vulnerable to an open redirect flaw. This security issue allows attackers to create malicious links that appear to be legitimate Mayan EDMS URLs but instead redirect users to external, potentially harmful websites. This can be used in phishing campaigns to steal user credentials or distribute malware by tricking employees into trusting the destination site.

Technical details

An open redirect vulnerability exists in Mayan EDMS due to insecure handling of the window.location object in client-side JavaScript templates. Specifically, the application improperly processes user-controlled values from the URL hash fragment (#) and the 'next' parameter within the /authentication/ path. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, leading to a redirection to an arbitrary external domain. The root cause is the lack of validation or sanitization of the URL fragment before it is appended to the navigation logic. The vendor has addressed this in version 4.10.2 by enforcing same-origin and HTTP-only redirection.

Affected products

  • Mayan EDMS Mayan EDMS < 4.6.12, 4.7.0 - 4.7.7, 4.8.0 - 4.8.9, 4.9.0 - 4.9.6, 4.10.0 - 4.10.1

Timeline

  • 2025-12-13: patched: Version 4.10.2 released with security hardening for navigation redirects.
  • 2025-12-15: advisory: GitHub Advisory and NVD entry published.

References

Related threats