Docmost 是一款开源的协作式维基和文档管理软件。在 0.80.1 版本之前,经过身份验证的用户可以存储由攻击者控制的 值,这些值在后续执行头像清理操作时会被重新使用,而在本地存储部署中,该清理过程缺乏对目标目录的限制,导致越权访问本地文件系统的风险。低权限用户可利用此漏洞删除 Docmost 服务账户可访问的任意本地文件或目录。该问题已在 0.80.1 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65827 | 6.5 MEDIUM | Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service |
| CVE-2026-48072 | 5.3 MEDIUM | Docmost: Public image fileName path traversal leads to unauthorized local file read |
| CVE-2026-52853 | 5.2 MEDIUM | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-52850 | 4.3 MEDIUM | Docmost: Broken access control in transclusion lookup API leaks sync-block content across |
| CVE-2026-48073 | 4.3 MEDIUM | Docmost: Page export can include restricted same-space attachments through forged attachme |
No comments yet