{"id":"CVE-2026-25642","summary":"HedgeDoc security headers for uploaded files were not working","details":"HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below the /uploads/ endpoint did not use a more strict security-policy. This resulted in a too open Content-Security-Policy and furthermore opened the possibility to host malicious interactive web content (such as fake login forms) using SVG files. This vulnerability is fixed in 1.10.6.","aliases":["GHSA-x74j-jmf9-534w"],"modified":"2026-08-12T03:51:18.747412013Z","published":"2026-02-06T19:23:59.991Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25642.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/hedgedoc/hedgedoc/releases/tag/1.10.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25642.json"},{"type":"ADVISORY","url":"https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-x74j-jmf9-534w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25642"},{"type":"FIX","url":"https://github.com/hedgedoc/hedgedoc/commit/74daa0e7a1cbfafd9aeb255eaf064dfe47cd401c"},{"type":"FIX","url":"https://github.com/hedgedoc/hedgedoc/commit/b930fe04cee92cd4723044030bb59c36781c7137"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hedgedoc/hedgedoc","events":[{"introduced":"0"},{"fixed":"145e3ee318ca0ed57598e18e405ff7229c8d74f8"},{"fixed":"74daa0e7a1cbfafd9aeb255eaf064dfe47cd401c"},{"fixed":"b930fe04cee92cd4723044030bb59c36781c7137"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:hedgedoc:hedgedoc:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.10.6"}]}}],"versions":["1.10.5","1.10.4","1.10.2","1.10.1","1.10.0","1.9.9","1.9.8","1.9.7","1.9.6","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.9.0-rc1","1.8.2","1.8.1","1.8.0","1.8.0-rc1","1.7.2","1.7.1","1.7.0","1.7.0-rc2","1.7.0-rc1","1.6.0","1.5.0","1.4.0","1.3.2","1.3.1","1.3.0","1.2.1","1.2.0","1.1.1-ce","1.1.0-ce","1.0.1-ce","1.0.0-ce","0.5.0","0.4.6","0.4.5","0.4.4","0.4.3","0.4.2","0.4.1","0.4.0","v0.3.4","v0.3.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25642.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}