Impact
The vulnerability lies in the authorize function of apps/web/server/auth.ts in karakeep-app. The function fails to enforce a restriction on repeated authentication attempts, allowing an attacker to submit unlimited credential guesses. This flaw can lead to account compromise via brute‑force attacks, increasing the risk of unauthorized access and potential data exposure. The weakness is an example of CWE‑307 and is also associated with CWE‑799.
Affected Systems
karakeep-app karakeep versions up to and including 0.32.0 are impacted. Versions 0.33.0 and later contain the fix; upgrading to that release resolves the issue. No other product or version information is available beyond the known affected range.
Risk and Exploitability
The CVSS base score of 6.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no current widespread exploitation activity. The attack vector is remote, with high complexity and difficult exploitability, but the public availability of the exploit means that determined adversaries could still target affected installations. Therefore, the risk remains significant enough to warrant prompt remediation.
OpenCVE Enrichment