Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

Twake: Unvalidated Input Can Execute Malicious Commands

CVE-2025-70039
Summary

A vulnerability in linagora Twake allows an attacker to inject malicious commands that can be executed on the system, potentially leading to unauthorized access or data corruption. This issue affects users who have installed the affected version of Twake. Update to the latest version to mitigate the risk.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
linagora twake 2023.q1.1223 –
Original title
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Original description
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Vulnerability type
CWE-78 OS Command Injection
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026