{"id":"CVE-2026-22249","summary":"Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)","details":"Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability is fixed in 0.24.0.","aliases":["GHSA-54pm-hqxm-54wg"],"modified":"2026-08-12T03:51:17.624255697Z","published":"2026-01-15T18:43:56.263Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22249.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/docmost/docmost/releases/tag/v0.24.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22249.json"},{"type":"ADVISORY","url":"https://github.com/docmost/docmost/security/advisories/GHSA-54pm-hqxm-54wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22249"},{"type":"FIX","url":"https://github.com/docmost/docmost/commit/c3b350d943108552e20654580005cd6f6c78ab05"},{"type":"FIX","url":"https://github.com/docmost/docmost/pull/1753"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docmost/docmost","events":[{"introduced":"65b01038d70c27b5d8b45bac8a6cc0efcc365936"},{"fixed":"0fe1459864ecc22582e5bae319537b30b705bacf"},{"fixed":"c3b350d943108552e20654580005cd6f6c78ab05"}],"database_specific":{"cpe":"cpe:2.3:a:docmost:docmost:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.21.0"},{"fixed":"0.24.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.23.2","v0.23.1","v0.23.0","v0.22.2","v0.22.1","v0.22.0","v0.21.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22249.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"}]}