CVE Explorer
CVE-2026-58489
HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only checked that it was present rather than validating it against the value expected for the user's session. Because the state was not properly validated, an attacker could forge a callback URL containing their own valid GitHub OAuth code. When processing the callback, HedgeDoc used the victim's logged-in session to select which note to
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"hedgedoc","vendor":"hedgedoc","versions":[{"status":"affected","version":"< 1.11.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:15735d1a280f50fe9639ae9bedd15e21d697bee7c63bffc3a7ab175d893010c4 · sha256:4170e7863bf9efda… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:15735d1a280f50fe9639ae9bedd15e21d697bee7c63bffc3a7ab175d893010c4 · sha256:4170e7863bf9efda… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:15735d1a280f50fe9639ae9bedd15e21d697bee7c63bffc3a7ab175d893010c4 · sha256:4170e7863bf9efda… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/hedgedoc/hedgedoc/commit/fbd7307f162754212046ec343cbe691223a48c8d","tags":["x_refsource_MISC"],"url":"https://github.com/hedgedoc/hedgedoc/commit/fbd7307f162754212046ec343cbe691223a48c8d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15735d1a280f50fe9639ae9bedd15e21d697bee7c63bffc3a7ab175d893010c4 · sha256:4170e7863bf9efda… · /containers/cna/references/1
{"name":"https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-8v9p-5j95-826j","tags":["x_refsource_CONFIRM"],"url":"https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-8v9p-5j95-826j"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:15735d1a280f50fe9639ae9bedd15e21d697bee7c63bffc3a7ab175d893010c4 · sha256:4170e7863bf9efda… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.