Outline是Outline开源的一个知识库。 Outline 0.84.0版本至1.6.1版本存在安全漏洞,该漏洞源于OAuthInterface.validateScope()中的逻辑错误使用Array.some()验证请求的OAuth范围,导致如果任何单个范围有效则接受整个范围数组,攻击者可通过请求范围read 来走私通配符范围,将只读OAuth令牌升级为包括写入、删除和管理操作在内的完全无限制API访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43888 | 8.7 HIGH | Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import |
| CVE-2026-43890 | 7.7 HIGH | Outline: IDOR in subscriptions.create allows cross-tenant subscription on private document |
| CVE-2026-43887 | 7.3 HIGH | Outline: Stored XSS via Comment Mentions |
| CVE-2026-43889 | 6.5 MEDIUM | Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share |
| CVE-2026-44695 | 5.8 MEDIUM | Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity |
No comments yet