{"id":"CVE-2026-48070","published":"2026-09-24T19:17:13.430","lastModified":"2026-09-24T19:17:13.560","description":"Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.","cvssScore":7.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5","tags":[]},{"url":"https://github.com/docmost/docmost/releases/tag/v0.80.1","tags":[]},{"url":"https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248","tags":[]}],"exploitRefs":[{"url":"https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5","tags":[]},{"url":"https://github.com/docmost/docmost/releases/tag/v0.80.1","tags":[]},{"url":"https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248","tags":[]}],"hasPoc":true,"ai":null}