CVE-2025-57231 | Docmost 0.21.0 Avatar Attachments attachment.controller.ts path traversal

SecurityVulns

A vulnerability was found in Docmost 0.21.0. It has been declared as critical. Affected by this issue is some unknown functionality of the file apps/server/src/core/attachment/attachment.controller.ts of the component Avatar Attachments. The manipulation results in path traversal.

This vulnerability is reported as CVE-2025-57231. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More