Skip to content
archivevulnerability · 18 Sep 2026 · 17:54 UTC

GHSA-xcw4-53cc-hv32: Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

VULNCVE-2026-59163source · GTH
HIGHCritical vulnerability — CVSS 9.1
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

### Summary The Mnemosyne sync server's authentication check decoded JWT bearer tokens but never verified their HMAC-SHA256 signatures. Any well-formed token was accepted, allowing an unauthenticated attacker to impersonate any user and read or modify their sync data. **Severity: Critical** CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N = 9.1 Assumes the sync server endpoint is network-reachable. If your deployment is localhost-only, the score drops substantially and severity becomes High or Medium depending on local exposure. Confirm your threat model. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected