Docmost 是一款开源的协作式维基和文档软件。在 0.80.1 版本之前,公开的头像和标志图片端点接受攻击者可控的 fileName 路径片段,并在未限制于预期图片目录的情况下将其解析为本地存储路径。未授权的攻击者可以遍历到头像或标志目录之外,读取本地存储中满足路由 UUID 检查条件的对象。该问题已在 0.80.1 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48070 | 7.1 HIGH | Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletio |
| CVE-2026-65827 | 6.5 MEDIUM | Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service |
| CVE-2026-52853 | 5.2 MEDIUM | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-52850 | 4.3 MEDIUM | Docmost: Broken access control in transclusion lookup API leaks sync-block content across |
| CVE-2026-48073 | 4.3 MEDIUM | Docmost: Page export can include restricted same-space attachments through forged attachme |
No comments yet