Home

Description

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.

PUBLISHED Reserved 2025-12-22 | Published 2026-02-11 | Updated 2026-02-12 | Assigner GitHub_M




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-287: Improper Authentication

Product status

< 1.1.0
affected

References

github.com/...utline/security/advisories/GHSA-mx2c-3g2x-5m9m

github.com/outline/outline/releases/tag/v1.1.0

cve.org (CVE-2025-68663)

nvd.nist.gov (CVE-2025-68663)

Download JSON