Outline是Outline开源的一个知识库。 Outline 1.7.0之前版本存在安全漏洞,该漏洞源于shares.create API同时接受collectionId和documentId且当published=false时仅验证每个的读取访问权限,跳过共享权限检查,后续shares.update使用OR策略授权发布,持有无关集合共享权限的攻击者可发布暴露其无法合法共享的任意文档的共享,使其对未经验证用户公开可访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43888 | 8.7 HIGH | Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import |
| CVE-2026-43886 | 8.2 HIGH | Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Ac |
| CVE-2026-43890 | 7.7 HIGH | Outline: IDOR in subscriptions.create allows cross-tenant subscription on private document |
| CVE-2026-43887 | 7.3 HIGH | Outline: Stored XSS via Comment Mentions |
| CVE-2026-44695 | 5.8 MEDIUM | Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity |
No comments yet