Security: outline/outline
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Timing-Unsafe Token Comparison in Unauthenticated Unsubscribe EndpointsGHSA-wgqc-257g-78v3 published
Jun 6, 2026 by tommoorLow -
Webhook subscription persists after creator's account deletionGHSA-33jq-x32c-3ccw published
Jun 6, 2026 by tommoorModerate -
Authorization Bypass in API Key/OAuth Scopes via Path Parsing DiscrepancyGHSA-5x79-rj4g-qrh8 published
Jun 15, 2026 by tommoorHigh -
MCP `list_documents` tool exact-match lookup leaks unauthorized document metadataGHSA-pp65-6cc2-4mx9 published
Jun 6, 2026 by tommoorModerate -
Slack OAuth state can link a victim Outline account to an attacker Slack identityGHSA-mjgw-5j7q-gv8v published
May 7, 2026 by tommoorModerate -
IDOR in subscriptions.create allows cross-tenant subscription on private documents (sibling of GHSA-23jj-rp48-w7q7)GHSA-gf8h-cv9v-q4fw published
May 7, 2026 by tommoorModerate -
OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API AccessGHSA-7732-6qrg-wjf4 published
May 7, 2026 by tommoorHigh -
Attachment Preset Size-Limit Bypass and Storage Accounting Corruption in Local-Storage ModeGHSA-hqmp-r5jw-265r published
Apr 25, 2026 by tommoorModerate -
Zip Extraction Path Escape via PATH_MAX Truncation in Collection ImportGHSA-hw32-2v7j-mgqc published
May 7, 2026 by tommoorHigh -
Unauthorized Document Publication via Mixed collectionId+documentId ShareGHSA-rg4j-pmch-w6pm published
May 7, 2026 by tommoorModerate