Junglewise Threat Intelligence

CVE-2026-54573: Outline authorization bypass via path parsing discrepancy

CVE-2026-54573 · Severity: info · CVSS 5.3 · Published 2026-06-25

Technologies: Outline.

Executive brief

Outline, a collaborative documentation platform, contains a security flaw in how it validates API permissions. An attacker with limited access (such as a read-only API key) can bypass security restrictions to perform unauthorized actions, like creating or modifying documents. This could lead to unauthorized data changes or privilege escalation within the workspace.

Technical details

An authorization bypass exists in Outline's AuthenticationHelper.canAccess function due to a discrepancy in how URLs are parsed compared to the Koa router. The function uses ctx.originalUrl to validate API key scopes by splitting the string at slashes and checking the last segment, but it fails to strip URL fragments (#). While the Koa router uses ctx.path (which excludes fragments) to direct the request to a restricted endpoint, the authorization check processes the full URL including the fragment. By appending a fragment containing a permitted resource name to a restricted path, an attacker with a low-privileged API key can trick the system into granting access to restricted endpoints. This allows for privilege escalation, such as using a read-only key to perform write operations. The issue is resolved in version 1.8.0.

Affected products

  • Outline Outline < 1.8.0

Timeline

  • 2026-06-15: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: CVE published to NVD

References