Home

Description

Docmost is open-source collaborative wiki and documentation software. From g and before 0.25.0, the public share page functionality in Docmost does not properly HTML-escape page titles before inserting them into meta tags and the title tag. This allows Stored Cross-Site Scripting (XSS) attacks, where an attacker can execute arbitrary JavaScript in the context of any user who opens a shared page link. This vulnerability is fixed in 0.25.0.

PUBLISHED Reserved 2026-01-20 | Published 2026-02-10 | Updated 2026-02-10 | Assigner GitHub_M




HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 0.20.0, < 0.25.0
affected

References

github.com/...ocmost/security/advisories/GHSA-h7fp-4f37-29wq exploit

github.com/...ocmost/security/advisories/GHSA-h7fp-4f37-29wq

github.com/...ommit/f3f74c591f32f85b8aa9a98ed884a7dd455780f9

github.com/docmost/docmost/releases/tag/v0.25.0

cve.org (CVE-2026-24045)

nvd.nist.gov (CVE-2026-24045)

Download JSON