Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

outline — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in outline, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability disclosures specifically for the software product "outline". It collects security advisories and defect reports associated with outline, covering incidents from the product's initial release through the most recent disclosed security updates. Here, users can track the vendor's advisory history, understand recurring weakness classes affecting the codebase, and review the complete vulnerability lifecycle for the application. The data reflects officially released patches and unpatched issues identified by security researchers or the development team. No specific CVE identifiers are listed in the introduction; instead, the focus remains on the structural relationship between the product and its known security flaws. Readers gain a consolidated view of risk exposure without navigating individual ticket systems.

Vendor: outline

CVE ID Title CVSS Severity Published
CVE-2026-54573 Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy CWE-863 - - 2026-06-25
CVE-2026-44695 Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity CWE-352 5.8 Medium 2026-05-11
CVE-2026-43889 Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share CWE-863 6.5 Medium 2026-05-11
CVE-2026-43888 Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import CWE-22 8.7 High 2026-05-11
CVE-2026-43890 Outline: IDOR in subscriptions.create allows cross-tenant subscription on private documents (sibling of GHSA-23jj-rp48-w7q7) CWE-639 7.7 High 2026-05-11
CVE-2026-43886 Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Access CWE-269 8.2 High 2026-05-11
CVE-2026-43887 Outline: Stored XSS via Comment Mentions CWE-79 7.3 High 2026-05-11
CVE-2026-41649 Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces CWE-639 7.7 High 2026-04-28
CVE-2026-33640 Outline has a rate limit bypass that allows brute force of email login OTP CWE-307 9.1 - 2026-03-26
CVE-2026-28506 Outline's Information Disclosure in Activity Logs allows User Enumeration of Private Drafts CWE-200 4.3 Medium 2026-03-17
CVE-2026-24901 Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts CWE-639 8.1 High 2026-03-17
CVE-2025-68663 Outline has a suspended user authentication bypass via WebSocket connections CWE-287 4.3AI Medium AI 2026-02-11
CVE-2025-64487 Outline is vulnerable to privilege escalation vulnerability in document sharing CWE-269 7.6 High 2026-02-11
CVE-2026-25062 Outline Affected an Arbitrary File Read via Path Traversal in JSON Import CWE-22 5.5 Medium 2026-02-11
CVE-2023-54331 Outline 1.6.0 - Unquoted Service Path CWE-428 7.8 High 2026-01-13
CVE-2025-58351 Outline's Local File Storage Feature can Cause CSP Bypass CWE-79 6.8 Medium 2025-09-03
CVE-2024-40626 Stored Cross-site Scripting (XSS) vulnerability in Outline editor CWE-79 7.3 High 2024-07-16

All 17 known CVE vulnerabilities affecting outline with full Chinese analysis, references, and POCs where available.