Impact
An improper authentication flaw exists in the OAuth Sign-In component of karakeep, affecting versions up to 0.32.0. The vulnerability arises from an undisclosed function in apps/web/server/auth.ts that allows an attacker to bypass normal authentication checks. A successful exploit would grant the attacker access to the application under the victim’s identity, potentially exposing sensitive data and enabling further attacks such as privilege escalation or data tampering. The weakness is categorized as CWE‑287 (Improper Authentication).
Affected Systems
The flaw impacts the karakeep web application, specifically the OAuth Sign-In feature in karakeep-app:karakeep up to version 0.32.0. There are no other vendor or product groups reported as affected.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. Because the EPSS score is not available and the issue is not listed in CISA KEV, the current knowledge of exploitation likelihood is limited. The public disclosure and the reported difficulty of the exploit suggest that while the attack requires remote access and has a relatively high complexity, it is still considered difficult to execute. Nonetheless, the possibility of unauthorized access mandates timely remediation.
OpenCVE Enrichment