CVE-2026-48070

high

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.

References

https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248

https://github.com/docmost/docmost/releases/tag/v0.80.1

https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86345

Details

Source: Mitre, NVD

Published: 2026-09-24

Updated: 2026-10-05

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:P

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Severity: High

EPSS

EPSS: 0.00369