Cross-Site Request Forgery Vulnerability in HedgeDoc's OAuth2 Endpoints
CVE-2025-66629
What is CVE-2025-66629?
HedgeDoc, an open-source collaborative markdown notes application, has a vulnerability affecting its OAuth2 endpoints. Prior to version 1.10.4, certain endpoints lacked proper CSRF protection, allowing potential attackers to exploit the absence of a state parameter for social login providers like Google, GitHub, GitLab, Facebook, and Dropbox. This vulnerability could enable unauthorized actions on behalf of unsuspecting users during the login process. The issue has been resolved in version 1.10.4, which includes additional security measures for safeguarding user authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
hedgedoc < 1.10.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
