PT-2026-98237 · Docmost · Docmost

CVE-2026-48072

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Docmost versions prior to 0.80.1
Description The public avatar and logo image endpoint allows an unauthenticated attacker to provide controlled fileName path segments. Because these segments are resolved against local storage without being confined to the intended image directory, a path traversal attack is possible. This allows the attacker to read local storage objects, provided the final basename of the file satisfies the route's UUID check.
Recommendations Update to version 0.80.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48072
GHSA-9F58-29HM-MGP2

Affected Products

Docmost