Junglewise Threat Intelligence

CVE-2026-54165: Dobase stored DOM-based XSS in shared image gallery

CVE-2026-54165 · Severity: info · CVSS 7.1 · Published 2026-09-11

Executive brief

Dobase is an open-source workspace platform that allows users to share file folders publicly. The image gallery in publicly shared folders contains a stored XSS vulnerability where an attacker with workspace access can embed malicious code in a filename. When a victim clicks on an image in the public gallery, arbitrary JavaScript code executes in their browser, potentially compromising their account or data.

Technical details

The vulnerability is a stored DOM-based cross-site scripting (XSS) in the public-gallery Stimulus controller. The root cause is a double-encoding bypass: file names are attacker-controlled via the rename endpoint and uploads with zero sanitization. The server-side ERB template escapes the name into a data-name attribute (appearing safe in HTML), but the browser DOM automatically decodes the attribute value, and the Stimulus controller then re-injects this raw payload into innerHTML without re-escaping. No authentication is required for the victim; any public share link is reachable. The attack requires an authenticated workspace member with folder-sharing rights to upload the malicious filename. The global Content-Security-Policy is report-only (not enforcing), so inline onerror handlers execute unblocked. Version 2026.06.03 patches the vulnerability.

Affected products

  • Dobase Dobase prior to 2026.06.03

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: patched: Version 2026.06.03

References