docs vulnerabilities
CVEs whose affected-version data names the docs package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92800Medium· 6.8PoCDocs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents
Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket s…
▾ Twilightsuitenumerique · DocsEPSS 0.24%via NVD
CVE-2026-91081Medium· 5.8Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID
Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-tim…
▾ Sunlitsuitenumerique · docsEPSS 0.25%via NVD