Description

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermore opened the possibility to host malicious interactive web content (such as fake login forms) using SVG files. This vulnerability is fixed in 1.10.6.

INFO

Published Date :

2026-02-06T19:23:59.991Z

Last Modified :

2026-02-06T20:20:58.376Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-25642 vulnerability.

Vendors Products
Hedgedoc
  • Hedgedoc

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact