---
id: CVE-2026-48073
title: Docmost is open-source collaborative wiki and documentation software
summary: >-
  Docmost is open-source collaborative wiki and documentation software. From
  0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an
  exportable page can embed a forged attachmentId that belongs to a restricted
  page in the …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: docmost
product: docmost
affected:
  - 'docmost >= 0.70.0, < 0.80.1'
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:17:29.000'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48073'
references:
  - url: >-
      https://github.com/docmost/docmost/commit/a573acedd0317f3472cb0f8b95f6aa15315312e5
    label: security-advisories@github.com
  - url: 'https://github.com/docmost/docmost/releases/tag/v0.80.1'
    label: security-advisories@github.com
  - url: 'https://github.com/docmost/docmost/security/advisories/GHSA-rxm9-xp9h-4c84'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T19:23:15.132872Z'
ingestedAt: '2026-09-24T18:49:36.722Z'
epss: 0.00193
epssPercentile: 0.07961
---

## Overview

Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the same space. Exporting the attacker-controlled page with includeAttachments=true causes the page export flow to read the restricted attachment from storage and include it in the returned ZIP archive even though direct file download denies access. This issue is fixed in version 0.80.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
