Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
Twake: Unvalidated Input Can Execute Malicious Commands
CVE-2025-70039
Summary
A vulnerability in linagora Twake allows an attacker to inject malicious commands that can be executed on the system, potentially leading to unauthorized access or data corruption. This issue affects users who have installed the affected version of Twake. Update to the latest version to mitigate the risk.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| linagora | twake | 2023.q1.1223 | – |
Original title
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Original description
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
Vulnerability type
CWE-78
OS Command Injection
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026