Path Traversal Vulnerability in Docmost Open-Source Documentation Software
CVE-2026-48072

5.3MEDIUM

Key Information:

Vendor

Docmost

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-48072?

The Docmost software, an open-source collaborative wiki and documentation platform, is vulnerable to a path traversal issue affecting versions prior to 0.80.1. The vulnerability allows an unauthenticated attacker to exploit the public avatar and logo image endpoint. By manipulating the fileName path segments, the attacker can access local storage files outside of the intended avatar and logo directories, potentially exposing sensitive information. This issue has been addressed in version 0.80.1, which confines file access to the designated image directories, thereby mitigating the risk of unauthorized data exposure. For further details and remediation, please refer to the updates in the official release.

Affected Version(s)

docmost < 0.80.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.