Cross-site request forgery in HedgeDoc - CVE-2025-66629

 

Cross-site request forgery in HedgeDoc - CVE-2025-66629

Published: April 25, 2026


Vulnerability identifier: #VU127924
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66629
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data by causing a victim to be logged into the attacker's account.

The vulnerability exists due to cross-site request forgery in OAuth2 callback endpoints when handling OAuth2 social login responses without a state parameter. A remote user can trick the victim into opening a crafted callback URL to disclose sensitive information and modify data by causing a victim to be logged into the attacker's account.

Only instances with an enabled affected social login provider are vulnerable, and user interaction is required to open the crafted URL.


Affected software

HedgeDoc

How to mitigate CVE-2025-66629

Install security update from vendor's website.

HedgeDoc - update to 1.10.4

External References

Related Security Bulletins