PT-2026-3091 · Docmost · Docmost

·

CVE-2026-22249

·

Published

2026-01-15

·

Updated

2026-01-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docmost versions 0.21.0 through 0.23.999
Description Docmost, an open-source collaborative wiki and documentation software, has a flaw where improper filename validation in the Zip Import Feature (ZipSlip) allows for arbitrary file writing. This occurs in apps/server/src/integrations/import/utils/file.utils.ts due to the lack of filename validation.
Recommendations Update to version 0.24.0 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22249
GHSA-54PM-HQXM-54WG

Affected Products

Docmost