Docmost 是一款开源的协作式维基和文档软件。在 0.90.1 版本之前,一个不属于私有工作区的经过身份认证的工作区成员,可以通过提供已知的 sourcePageId 和 transclusionId 配对,调用 transclusion / sync-block 查找 API。这是因为在解析源页面之前,该查找操作未强制验证私有工作区的成员身份。因此,尽管普通页面 API 会拒绝访问同一页面,该 API 仍可能返回敏感的 sync-block 内容和源页面的元数据。此问题已在 0.90.1 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48070 | 7.1 HIGH | Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletio |
| CVE-2026-65827 | 6.5 MEDIUM | Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service |
| CVE-2026-48072 | 5.3 MEDIUM | Docmost: Public image fileName path traversal leads to unauthorized local file read |
| CVE-2026-52853 | 5.2 MEDIUM | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-48073 | 4.3 MEDIUM | Docmost: Page export can include restricted same-space attachments through forged attachme |
No comments yet