Executive brief
Dobase is an open-source workspace platform that allows users to share file folders publicly. The image gallery in publicly shared folders contains a stored XSS vulnerability where an attacker with workspace access can embed malicious code in a filename. When a victim clicks on an image in the public gallery, arbitrary JavaScript code executes in their browser, potentially compromising their account or data.
Technical details
The vulnerability is a stored DOM-based cross-site scripting (XSS) in the public-gallery Stimulus controller. The root cause is a double-encoding bypass: file names are attacker-controlled via the rename endpoint and uploads with zero sanitization. The server-side ERB template escapes the name into a data-name attribute (appearing safe in HTML), but the browser DOM automatically decodes the attribute value, and the Stimulus controller then re-injects this raw payload into innerHTML without re-escaping. No authentication is required for the victim; any public share link is reachable. The attack requires an authenticated workspace member with folder-sharing rights to upload the malicious filename. The global Content-Security-Policy is report-only (not enforcing), so inline onerror handlers execute unblocked. Version 2026.06.03 patches the vulnerability.
Affected products
- Dobase Dobase prior to 2026.06.03
Timeline
- 2026-06-03: disclosed
- 2026-06-03: patched: Version 2026.06.03