A vulnerability categorized as problematic has been discovered in karakeep-app karakeep up to 0.32.0. The affected element is the function
authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.
This vulnerability was named CVE-2026-75773. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to upgrade the affected component.