Executive brief
GROWI is a popular open-source wiki and knowledge management platform. This vulnerability allows an authenticated attacker to retrieve, modify, or delete other users' bookmarks through improper authorization checks in the API, potentially exposing or corrupting sensitive user data stored within the platform.
Technical details
The vulnerability is an authorization bypass (CWE-639) in GROWI's bookmark folder APIs where user-controlled keys are used without proper validation. An authenticated attacker can manipulate API requests to access, modify, or delete bookmark data belonging to other users. The vulnerability requires authentication to exploit but does not require user interaction. The attack is network-accessible. A patch is available in GROWI v8.0.1 and later.
Affected products
- GROWI GROWI v8.0.0 and earlier
Timeline
- 2026-08-31: disclosed
- 2026-08-28: patched: GROWI v8.0.1 released