Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-48070

HIGH NVD
CVSS Score 7.1
Severity HIGH
Published Sep 24, 2026
Vendor unknown

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.

References