---
id: CVE-2026-59262
title: >-
  AFFiNE's histories GraphQL field fails to validate Doc.Read permission before
  exposing document edit history, allowing authenticated workspace members to
  retrieve restricted content timelines
summary: >-
  AFFiNE's histories GraphQL field fails to validate Doc.Read permission before
  exposing document edit history, allowing authenticated workspace members to
  retrieve restricted content timelines. Attackers can supply arbitrary document
  GUID…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: affine
product: monorepo
affected:
  - monorepo < 0.26.3
  - monorepo <= 1f0bcd0
published: '2026-07-08'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:16:54.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59262'
references:
  - url: 'https://github.com/toeverything/AFFiNE'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/toeverything/AFFiNE/commit/1f0bcd01a37a522393fc1b288395e3a72a79ccad
    label: disclosure@vulncheck.com
  - url: 'https://github.com/toeverything/AFFiNE/issues/15179'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/affine-unauthorized-document-edit-history-access-via-graphql-histories-field
    label: disclosure@vulncheck.com
  - url: 'https://github.com/toeverything/AFFiNE/issues/15179'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-08T17:43:26.413343Z'
epss: 0.00303
epssPercentile: 0.23219
ingestedAt: '2026-09-17T18:25:15.975Z'
---

## Overview

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted content timelines. Attackers can supply arbitrary document GUIDs to access full edit histories including user names, emails, and timestamps of private pages they lack access to.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
