VYPR

Mnemosyne

by Mnemosyne

CVEs (1)

  • CVE-2026-59163criSep 18, 2026
    risk 0.52cvss epss

    ### Summary The Mnemosyne sync server's authentication check decoded JWT bearer tokens but never verified their HMAC-SHA256 signatures. Any well-formed token was accepted, allowing an unauthenticated attacker to impersonate any user and read or modify their sync data. …