A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation r…
Low CVSS 3.7
Summary
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient t…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/karakeep-app/karakeep/
- https://github.com/karakeep-app/karakeep/commit/f7d042971d0d2bcc7119654830cf1eb93eabbf24
- https://github.com/karakeep-app/karakeep/issues/2919
- https://github.com/karakeep-app/karakeep/releases/tag/mcp/v0.33.0
- https://vuldb.com/cve/CVE-2026-75773
- https://vuldb.com/submit/877731
- https://vuldb.com/vuln/391519
- https://vuldb.com/vuln/391519/cti
Timeline
- nvd_ingest NVD