CVE-2026-48073
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the same space. Exporting the attacker-controlled page with includeAttachments=true causes the page export flow to read the restricted attachment from storage and include it in the returned ZIP archive even though direct file download denies access. This issue is fixed in version 0.80.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| docmost | docmost | >= 0.70.0, < 0.80.1 | affected |
Weaknesses
- CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/docmost/docmost/security/advisories/GHSA-rxm9-xp9h-4c84
- https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5
- https://github.com/docmost/docmost/releases/tag/v0.80.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.