Cross-Site Request Forgery Vulnerability in HedgeDoc's OAuth2 Endpoints
CVE-2025-66629
3.7LOW
What is CVE-2025-66629?
HedgeDoc, an open-source collaborative markdown notes application, has a vulnerability affecting its OAuth2 endpoints. Prior to version 1.10.4, certain endpoints lacked proper CSRF protection, allowing potential attackers to exploit the absence of a state parameter for social login providers like Google, GitHub, GitLab, Facebook, and Dropbox. This vulnerability could enable unauthorized actions on behalf of unsuspecting users during the login process. The issue has been resolved in version 1.10.4, which includes additional security measures for safeguarding user authentication.
Affected Version(s)
hedgedoc < 1.10.4
