---
id: CVE-2026-48072
title: Docmost is open-source collaborative wiki and documentation software
summary: >-
  Docmost is open-source collaborative wiki and documentation software. Prior to
  0.80.1, the public avatar and logo image endpoint accepts attacker-controlled
  fileName path segments and resolves them against local storage without
  confineme…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: docmost
product: docmost
affected:
  - docmost < 0.80.1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:17:13.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48072'
references:
  - url: >-
      https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5
    label: security-advisories@github.com
  - url: >-
      https://github.com/docmost/docmost/commit/ec83fc82d54bf3728eaa63b20eb4abcb5aef1d97
    label: security-advisories@github.com
  - url: 'https://github.com/docmost/docmost/releases/tag/v0.80.1'
    label: security-advisories@github.com
  - url: 'https://github.com/docmost/docmost/security/advisories/GHSA-9f58-29hm-mgp2'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-24T18:47:04.473169Z'
ingestedAt: '2026-09-24T18:49:36.718Z'
---

## Overview

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement to the intended image directory. An unauthenticated attacker can traverse outside the avatar or logo directory and read local storage objects whose final basename satisfies the route's UUID check. This issue is fixed in version 0.80.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
