{"id":"CVE-2020-11536","details":"An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit the unzip function to rewrite a binary and remotely execute code on a victim's server.","modified":"2026-03-15T14:36:38.944342Z","published":"2020-04-15T15:15:19.730Z","references":[{"type":"ADVISORY","url":"https://gist.github.com/andrewaeva/beb92d3d2f1c5672dbda5050e323f6a0"},{"type":"ADVISORY","url":"https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#551"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/onlyoffice/documentserver","events":[{"introduced":"0"},{"last_affected":"d93c9b34667f5ed750309997bd84e9cde5cff213"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"5.5.0"}]}}],"versions":["ONLYOFFICE-DocumentServer-3.0.0","ONLYOFFICE-DocumentServer-4.0.0-9","ONLYOFFICE-DocumentServer-4.0.1-34","ONLYOFFICE-DocumentServer-4.0.2-4","ONLYOFFICE-DocumentServer-4.0.3-3","ONLYOFFICE-DocumentServer-4.1.2-37","ONLYOFFICE-DocumentServer-4.1.4-3","ONLYOFFICE-DocumentServer-4.1.5-1","ONLYOFFICE-DocumentServer-4.1.6-3","ONLYOFFICE-DocumentServer-4.1.8-1","ONLYOFFICE-DocumentServer-4.2.0","ONLYOFFICE-DocumentServer-4.2.1","ONLYOFFICE-DocumentServer-4.2.10","ONLYOFFICE-DocumentServer-4.2.11","ONLYOFFICE-DocumentServer-4.2.3","ONLYOFFICE-DocumentServer-4.2.4","ONLYOFFICE-DocumentServer-4.2.5","ONLYOFFICE-DocumentServer-4.2.7","ONLYOFFICE-DocumentServer-4.2.8","ONLYOFFICE-DocumentServer-4.2.9","ONLYOFFICE-DocumentServer-4.3.0","ONLYOFFICE-DocumentServer-4.3.1","ONLYOFFICE-DocumentServer-4.3.2","ONLYOFFICE-DocumentServer-4.3.3","ONLYOFFICE-DocumentServer-4.3.4","ONLYOFFICE-DocumentServer-4.3.5","ONLYOFFICE-DocumentServer-4.3.6","ONLYOFFICE-DocumentServer-4.4.1","ONLYOFFICE-DocumentServer-4.4.2","ONLYOFFICE-DocumentServer-4.4.3","ONLYOFFICE-DocumentServer-5.0.3","ONLYOFFICE-DocumentServer-5.0.4","ONLYOFFICE-DocumentServer-5.0.5","ONLYOFFICE-DocumentServer-5.0.6","ONLYOFFICE-DocumentServer-5.0.7","ONLYOFFICE-DocumentServer-5.1.0","ONLYOFFICE-DocumentServer-5.1.1","ONLYOFFICE-DocumentServer-5.1.2","ONLYOFFICE-DocumentServer-5.1.3","ONLYOFFICE-DocumentServer-5.1.4","ONLYOFFICE-DocumentServer-5.1.5","ONLYOFFICE-DocumentServer-5.2.0","ONLYOFFICE-DocumentServer-5.2.2","ONLYOFFICE-DocumentServer-5.2.3","ONLYOFFICE-DocumentServer-5.2.4","ONLYOFFICE-DocumentServer-5.2.6","ONLYOFFICE-DocumentServer-5.2.7","ONLYOFFICE-DocumentServer-5.2.8","ONLYOFFICE-DocumentServer-5.3.0","ONLYOFFICE-DocumentServer-5.3.1","ONLYOFFICE-DocumentServer-5.3.2","ONLYOFFICE-DocumentServer-5.3.4","ONLYOFFICE-DocumentServer-5.4.0-2","ONLYOFFICE-DocumentServer-5.4.1","ONLYOFFICE-DocumentServer-5.4.2","ONLYOFFICE-DocumentServer-5.5.0","ONLYOFFICE-Online-Editors-2.5","ONLYOFFICE-Online-Editors-2.5.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11536.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}