CVE-2026-48072

Source
https://cve.org/CVERecord?id=CVE-2026-48072
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-48072.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-48072
Aliases
  • GHSA-9f58-29hm-mgp2
Published
2026-09-24T18:30:57Z
Modified
2026-09-25T03:48:35Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Docmost: Public image fileName path traversal leads to unauthorized local file read
Details

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement to the intended image directory. An unauthenticated attacker can traverse outside the avatar or logo directory and read local storage objects whose final basename satisfies the route's UUID check. This issue is fixed in version 0.80.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48072.json"
}
References

Affected packages

Git / github.com/docmost/docmost

Affected ranges

Type
GIT
Repo
https://github.com/docmost/docmost
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.80.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.3
v0.*
v0.10.0
v0.10.1
v0.10.2
v0.2.0
v0.2.1
v0.2.10
v0.2.2
v0.2.4
v0.2.5
v0.2.7
v0.2.8
v0.2.9
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.21.0
v0.22.0
v0.22.1
v0.22.2
v0.23.0
v0.23.1
v0.23.2
v0.24.0
v0.24.1
v0.25.0
v0.25.0-beta.1
v0.25.1
v0.25.2
v0.25.3
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.5.0
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.70.0
v0.70.1
v0.70.2
v0.70.3
v0.71.0
v0.71.1
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-48072.json"