Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

outline — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting outline. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Outline is a collaborative note-taking and knowledge management tool used for organizing information and team collaboration. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) flaws, and privilege escalation issues. The application's web interface and API have been primary attack vectors, with several critical flaws allowing unauthorized access or system compromise. While no major public security incidents have been widely reported, the 11 documented CVEs indicate a pattern of security challenges that require ongoing vigilance. Users should ensure timely patching and implement proper access controls to mitigate risks associated with these vulnerabilities.

Top products by outline: outline outline/outline
CVE ID Title CVSS Severity Published
CVE-2026-54573 Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy — outline CWE-863 - - 2026-06-25
CVE-2026-44695 Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity — outline CWE-352 5.8 Medium 2026-05-11
CVE-2026-43889 Outline: Unauthorized Document Publication via Mixed collectionId+documentId Share — outline CWE-863 6.5 Medium 2026-05-11
CVE-2026-43888 Outline: Zip Extraction Path Escape via PATH_MAX Truncation in Collection Import — outline CWE-22 8.7 High 2026-05-11
CVE-2026-43890 Outline: IDOR in subscriptions.create allows cross-tenant subscription on private documents (sibling of GHSA-23jj-rp48-w7q7) — outline CWE-639 7.7 High 2026-05-11
CVE-2026-43886 Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Access — outline CWE-269 8.2 High 2026-05-11
CVE-2026-43887 Outline: Stored XSS via Comment Mentions — outline CWE-79 7.3 High 2026-05-11
CVE-2026-41649 Outline has IDOR in document share creation that allows unauthorized access to private documents across workspaces — outline CWE-639 7.7 High 2026-04-28
CVE-2026-33640 Outline has a rate limit bypass that allows brute force of email login OTP — outline CWE-307 9.1 - 2026-03-26
CVE-2026-28506 Outline's Information Disclosure in Activity Logs allows User Enumeration of Private Drafts — outline CWE-200 4.3 Medium 2026-03-17
CVE-2026-24901 Outline's IDOR allows unauthorized viewing and seizing of private deleted drafts — outline CWE-639 8.1 High 2026-03-17
CVE-2025-68663 Outline has a suspended user authentication bypass via WebSocket connections — outline CWE-287 4.3AI Medium AI 2026-02-11
CVE-2025-64487 Outline is vulnerable to privilege escalation vulnerability in document sharing — outline CWE-269 7.6 High 2026-02-11
CVE-2026-25062 Outline Affected an Arbitrary File Read via Path Traversal in JSON Import — outline CWE-22 5.5 Medium 2026-02-11
CVE-2025-58351 Outline's Local File Storage Feature can Cause CSP Bypass — outline CWE-79 6.8 Medium 2025-09-03
CVE-2024-40626 Stored Cross-site Scripting (XSS) vulnerability in Outline editor — outline CWE-79 7.3 High 2024-07-16
CVE-2023-3532 Cross-site Scripting (XSS) - Stored in outline/outline — outline/outline CWE-79 5.4 - 2023-07-07
CVE-2022-2342 Cross-site Scripting (XSS) - Stored in outline/outline — outline/outline CWE-79 5.4 - 2022-07-07

This page lists every published CVE security advisory associated with outline. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.