ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44695
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in Outline user complete the callback and link that user's Outline account to the attacker's Slack team_id and user_id. The linked Slack identity can then use the Slack /outline search command as the victim Outline user. This vulnerability is fixed in 1.7.1.

NVD description · AI analysis pending
6.5<1% PoC
  • getoutline outline
CVE-2026-41649
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the `documents.info` endpoint. Version 1.7.0 contains a patch.

NVD description · AI analysis pending
7.7<1% PoC
  • getoutline outline
CVE-2026-33640
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submissions, rather it relies on the rate limiter to restrict attempts. Consequently, identified bypasses in the rate limiter permit unrestricted OTP code submissions within the codes lifetime. This allows attackers to perform brute force attacks which enable account takeover. Version 1.6.0 fixes the issue.

NVD description · AI analysis pending
9.1<1% PoC
  • getoutline outline
CVE-2026-24901
+1 in the same advisory: …28506
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document restoration logic allows any team member to unauthorizedly restore, view, and seize ownership of deleted drafts belonging to other users, including administrators. By bypassing ownership validation during the restore process, an attacker can access sensitive private information and effectively lock the original owner out of their own content. Version 1.4.0 fixes the issue.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • getoutline outline
CVE-2025-64487
+2 in the same advisory: …68663 …25062
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1.0.

NVD description · AI analysis pending
7.6
group max
<1%
  • getoutline outline
CVE-2023-54331
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges.

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

NVD description · AI analysis pending
8.5<1% PoC
  • getoutline outline
CVE-2025-58351
Outline is a service that allows for collaborative documentation.

Outline is a service that allows for collaborative documentation. In versions 0.72.0 through 0.83.0, Outline introduced a feature which facilitates local file system storage capabilities as an optional file storage strategy. This feature allowed a CSP bypass as well as a ContentType bypass that might facilitate further attacks. In the case of self-hosting and using Outline FILE_STORAGE=local on the same domain as the Outline application, a malicious payload can be uploaded as a file attachment and bypass those CSP restrictions, allowing script execution within the context of another user. This is fixed in version 0.84.0.

NVD description · AI analysis pending
6.8<1%
  • getoutline outline
CVE-2024-40626
Outline is an open source, collaborative document editor.

Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated user can create a document containing a malicious JavaScript payload. When other users view this document, the malicious Javascript can execute in the origin of Outline. Outline includes CSP rules to prevent third-party code execution, however in the case of self-hosting and having your file storage on the same domain as Outline a malicious payload can be uploaded as a file attachment and bypass those CSP restrictions. This issue has been addressed in release version 0.77.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
5.4<1% PoC
  • getoutline outline
CVE-2024-37829
+1 in the same advisory: …37830
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.

An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in link.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • getoutline outline
CVE-2023-3532
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

NVD description · AI analysis pending
5.4<1% PoC
  • getoutline outline
CVE-2022-2342
Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.

NVD description · AI analysis pending
5.4<1% PoC
  • getoutline outline