THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xcw4-53cc-hv32 (critical) — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

[GHSA] GHSA-xcw4-53cc-hv32 (critical) — Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

medgithub_advisoriesPublished 2026-09-18

GHSA-xcw4-53cc-hv32 Severity: critical CVE: CVE-2026-59163

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

### Summary

The Mnemosyne sync server's authentication check decoded JWT bearer tokens but never verified their HMAC-SHA256 signatures. Any well-formed token was accepted, allowing an unauthenticated attacker to impersonate any user and read or

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xcw4-53cc-hv32