PT-2026-3877 · Docmost+1 · Docmost+1

Arthurgervais

+1

·

Publicado

2026-01-21

·

Atualizado

2026-02-17

·

CVE-2026-23630

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Docmost versions 0.3.0 through 0.23.2
Description Docmost is collaborative wiki and documentation software. Versions 0.3.0 through 0.23.2 are susceptible to stored Cross-Site Scripting (XSS) due to improper sanitization when rendering Mermaid code blocks. The mermaid.render() function is used to render diagrams, and the resulting SVG/HTML is injected into the Document Object Model (DOM) using dangerouslySetInnerHTML without appropriate sanitization. Mermaid’s %%{init}%% directives can override security settings and enable HTML labels, allowing arbitrary HTML and JavaScript execution for anyone viewing the diagrams.
Recommendations Update to version 0.24.0 or later.

Exploit

Correção

XSS

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23630
GHSA-R4HJ-MC62-JMWJ

Produtos afetados

Docmost
Mermaid