Docmost 是一款开源的协作式维基与文档管理软件。在版本 0.21.0 至 0.95.0 之间,任何具有编辑权限的已认证工作空间成员均可通过“页面导入”功能上传归档文件。该功能的 ZIP 解压缩过程未对总解压大小、单个条目大小或条目数量进行限制。解压器会将条目写入服务器的临时目录,并自动解压嵌套的 ZIP 文件。因此,即使外层上传受限于默认的 200 MB 大小限制,实际解压后仍可能膨胀至数 GB。由此引发的磁盘空间耗尽可能导致导入工作进程崩溃,进而影响或导致所有租户所在实例的服务降级或不可用。该问题已在 0.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48070 | 7.1 HIGH | Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletio |
| CVE-2026-48072 | 5.3 MEDIUM | Docmost: Public image fileName path traversal leads to unauthorized local file read |
| CVE-2026-52853 | 5.2 MEDIUM | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-52850 | 4.3 MEDIUM | Docmost: Broken access control in transclusion lookup API leaks sync-block content across |
| CVE-2026-48073 | 4.3 MEDIUM | Docmost: Page export can include restricted same-space attachments through forged attachme |
No comments yet