Outline是Outline开源的一个知识库。 Outline 0.84.0版本至1.6.1版本存在跨站脚本漏洞,该漏洞源于评论部分允许用户提及他人,但后端未验证或清理与这些提及关联的href属性,导致潜在危险协议未被过滤,存在客户端代码执行风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43888 | 8.7 HIGH | Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import |
| CVE-2026-43886 | 8.2 HIGH | Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Ac |
| CVE-2026-43890 | 7.7 HIGH | Outline: IDOR in subscriptions.create allows cross-tenant subscription on private document |
| CVE-2026-43889 | 6.5 MEDIUM | Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share |
| CVE-2026-44695 | 5.8 MEDIUM | Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity |
No comments yet