Docmost 是一款开源的协同维基和文档软件。在版本 0.70.0 至 0.80.1 中,拥有较低权限的已认证用户若能编辑一个可导出的页面,便可嵌入一个同空间内受限制页面的伪造 attachmentId(附件 ID)。当攻击者控制该页面并设置 includeAttachments=true 参数进行导出时,导出流程会从存储中读取该受限制的附件,并将其包含在返回的 ZIP 归档文件中,尽管直接下载该文件会被拒绝访问。此问题已在版本 0.80.1 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48070 | 7.1 HIGH | Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletio |
| CVE-2026-65827 | 6.5 MEDIUM | Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service |
| CVE-2026-48072 | 5.3 MEDIUM | Docmost: Public image fileName path traversal leads to unauthorized local file read |
| CVE-2026-52853 | 5.2 MEDIUM | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-52850 | 4.3 MEDIUM | Docmost: Broken access control in transclusion lookup API leaks sync-block content across |
No comments yet