CVE-2026-48070 UNKNOWN

CVE-2026-48070

Published: 2026-09-24

Description

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…