Outline是Outline开源的一个知识库。 Outline 1.7.0之前版本存在路径遍历漏洞,该漏洞源于ZipHelper.extract在计算提取路径时通过trimFileAndExt传递完整文件系统路径,当zip条目的嵌套路径足够长时,trimFileAndExt静默丢弃所有目录组件并返回裸文件名,导致文件在进程工作目录而非提取沙箱内打开,且转义文件在导入清理后持续存在。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43886 | 8.2 HIGH | Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Ac |
| CVE-2026-43890 | 7.7 HIGH | Outline: IDOR in subscriptions.create allows cross-tenant subscription on private document |
| CVE-2026-43887 | 7.3 HIGH | Outline: Stored XSS via Comment Mentions |
| CVE-2026-43889 | 6.5 MEDIUM | Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share |
| CVE-2026-44695 | 5.8 MEDIUM | Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity |
No comments yet