{"id":"CVE-2026-48070","title":"Docmost is open-source collaborative wiki and documentation software","summary":"Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directo…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwe":["CWE-22"],"vendor":"docmost","product":"docmost","affected":["docmost < 0.80.1"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T19:17:13.560","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48070","references":[{"url":"https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5","label":"security-advisories@github.com"},{"url":"https://github.com/docmost/docmost/releases/tag/v0.80.1","label":"security-advisories@github.com"},{"url":"https://github.com/docmost/docmost/security/advisories/GHSA-95f8-h5hf-8248","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T18:49:36.723Z","slug":"CVE-2026-48070","body":"## Overview\n\nDocmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}