CVE-2026-48070
7.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Summary
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| docmost | docmost | < 0.80.1 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248
- https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5
- https://github.com/docmost/docmost/releases/tag/v0.80.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.