Path Traversal Vulnerability in Docmost Open-Source Documentation Software
CVE-2026-48072
5.3MEDIUM
What is CVE-2026-48072?
The Docmost software, an open-source collaborative wiki and documentation platform, is vulnerable to a path traversal issue affecting versions prior to 0.80.1. The vulnerability allows an unauthenticated attacker to exploit the public avatar and logo image endpoint. By manipulating the fileName path segments, the attacker can access local storage files outside of the intended avatar and logo directories, potentially exposing sensitive information. This issue has been addressed in version 0.80.1, which confines file access to the designated image directories, thereby mitigating the risk of unauthorized data exposure. For further details and remediation, please refer to the updates in the official release.
Affected Version(s)
docmost < 0.80.1
