Cross-Site Request Forgery Vulnerability in HedgeDoc's OAuth2 Endpoints
CVE-2025-66629

3.7LOW

Key Information:

Vendor

Hedgedoc

Status
Vendor
CVE Published:
5 December 2025

What is CVE-2025-66629?

HedgeDoc, an open-source collaborative markdown notes application, has a vulnerability affecting its OAuth2 endpoints. Prior to version 1.10.4, certain endpoints lacked proper CSRF protection, allowing potential attackers to exploit the absence of a state parameter for social login providers like Google, GitHub, GitLab, Facebook, and Dropbox. This vulnerability could enable unauthorized actions on behalf of unsuspecting users during the login process. The issue has been resolved in version 1.10.4, which includes additional security measures for safeguarding user authentication.

Affected Version(s)

hedgedoc < 1.10.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66629 : Cross-Site Request Forgery Vulnerability in HedgeDoc's OAuth2 Endpoints