CVE-2026-22249

HIGH

Docmost < 0.24.0 - Path Traversal

Title source: rule
STIX 2.1

Description

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability is fixed in 0.24.0.

Scores

CVSS v3 7.1
EPSS 0.0003
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
docmost/docmost 0.21.0 - 0.24.0
Published Jan 15, 2026
Tracked Since Feb 18, 2026