Outline是Outline开源的一个知识库。 Outline 1.7.1之前版本存在跨站请求伪造漏洞,该漏洞源于Slack集成回调接受未签名的OAuth状态值,可能导致第三方将用户账户链接到攻击者的Slack团队。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43888 | 8.7 HIGH | Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import |
| CVE-2026-43886 | 8.2 HIGH | Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Ac |
| CVE-2026-43890 | 7.7 HIGH | Outline: IDOR in subscriptions.create allows cross-tenant subscription on private document |
| CVE-2026-43887 | 7.3 HIGH | Outline: Stored XSS via Comment Mentions |
| CVE-2026-43889 | 6.5 MEDIUM | Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share |
No comments yet