THREAT OPS › Threat News › [GHSA] GHSA-xcw4-53cc-hv32 (critical) — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
[GHSA] GHSA-xcw4-53cc-hv32 (critical) — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
GHSA-xcw4-53cc-hv32 Severity: critical CVE: CVE-2026-59163
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
### Summary
The Mnemosyne sync server's authentication check decoded JWT bearer tokens but never verified their HMAC-SHA256 signatures. Any well-formed token was accepted, allowing an unauthenticated attacker to impersonate any user and read or
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-59163cve
Original source: https://github.com/advisories/GHSA-xcw4-53cc-hv32