Impact
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url. This is a CWE-22 path traversal vulnerability.
Affected Systems
Docmost 0.21.0 installed in any environment with the avatar upload endpoint exposed. The flaw exists in the core attachment controller where paths are not properly sanitised; vulnerability is a path traversal flaw in the avatar attachment handling code of Docmost version 0.21.0. An attacker can construct a POST request to a public endpoint and supply a file path containing traversal characters that causes the server to read arbitrary files from the local filesystem. Successful exploitation or any other file the server process can access, leading to a compromise of confidentiality.
Risk and Exploitability
The flaw is exploitable without authentication over the network via a simple POST request to a public URL. The CVSS score of 7.5 reflects a high severity, and the EPSS low probability of exploitation, though the vulnerability is still not listed in CISA KEV. Because it permits arbitrary local file reads, it could be severe if sensitive files are accessible.
OpenCVE Enrichment