Executive brief
Outline, a collaborative documentation platform, contains a security flaw in its Slack integration. An attacker can trick a logged-in user into clicking a malicious link that connects the user's Outline account to the attacker's Slack account. Once linked, the attacker can use Slack commands to search for and view private document titles, summaries, and links belonging to the victim.
Technical details
The Slack integration callback for 'GET /auth/slack.post' fails to properly validate the OAuth 'state' parameter, accepting unsigned and session-independent values. This lack of a nonce or cryptographic signature allows for a Cross-Site Request Forgery (CSRF) style attack where an attacker can provide their own Slack OAuth code and state to a logged-in victim. When the victim's browser processes the callback, the server creates an 'IntegrationType.LinkedAccount' row mapping the victim's Outline 'userId' to the attacker's Slack 'team_id' and 'user_id'. Consequently, the attacker can execute the '/outline' search command from their Slack workspace to retrieve search results (titles, snippets, and links) authorized for the victim user. This issue is resolved in version 1.7.1.
Affected products
- Outline Outline < 1.7.1
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published by maintainers
- 2026-05-11: disclosed: CVE published to NVD
- 2026-05-11: patched: Fix released in version 1.7.1