CVE-2025-66629 | HedgeDoc up to 1.10.3 OAuth2 Endpoint cross-site request forgery (GHSA-6wm6-3vpq-6qvv / EUVD-2025-201504)
A vulnerability described as problematic has been identified in HedgeDoc up to 1.10.3. Affected is an unknown function of the component OAuth2 Endpoint. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-66629. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.