CVE-2024-40626

Stored Cross-site Scripting (XSS) vulnerability in Outline editor

Description

Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated user can create a document containing a malicious JavaScript payload. When other users view this document, the malicious Javascript can execute in the origin of Outline. Outline includes CSP rules to prevent third-party code execution, however in the case of self-hosting and having your file storage on the same domain as Outline a malicious payload can be uploaded as a file attachment and bypass those CSP restrictions. This issue has been addressed in release version 0.77.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Category

7.3
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.07%
Affected: outline outline
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-40626?
CVE-2024-40626 has been scored as a high severity vulnerability.
How to fix CVE-2024-40626?
To fix CVE-2024-40626, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-40626 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-40626 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-40626?
CVE-2024-40626 affects outline outline.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.