Description
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermore opened the possibility to host malicious interactive web content (such as fake login forms) using SVG files. This vulnerability is fixed in 1.10.6.
INFO
Published Date :
2026-02-06T19:23:59.991Z
Last Modified :
2026-02-06T20:20:58.376Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-25642 vulnerability.
| Vendors | Products |
|---|---|
| Hedgedoc |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-25642.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact