Junglewise Threat Intelligence

CVE-2026-80191: GROWI authorization bypass in attachment retrieval

CVE-2026-80191 · Severity: high · CVSS 7.5 · Published 2026-08-26

Technologies: GROWI.

Executive brief

GROWI is a team collaboration platform that allows users to create and share markdown pages with access controls. An unauthenticated attacker who knows the identifier of a private attachment can bypass the permission system and download the file without authentication, even if the page is marked private and they would not normally have access. This allows sensitive documents and files to be exposed if their identifiers are leaked or guessed.

Technical details

The vulnerability is an authorization bypass in the attachment download functionality. The retrieveAttachmentFromIdParam function in apps/app/src/server/routes/attachment/get.ts guards permission checks with a condition that requires an authenticated user (non-null user), causing unauthenticated requests to skip the check entirely. The routes /attachment/:id and /download/:id take the attachment identifier from the URL path and return the file without verifying page-viewer permissions for requests without a session. An unauthenticated attacker can retrieve any attachment file if they possess or can guess its identifier, regardless of whether the containing page is private or marked for restricted access. The vulnerability was fixed in version 8.0.2, which applies the permission check to both authenticated and unauthenticated requests.

Affected products

  • GROWI GROWI before 8.0.2

Timeline

  • 2026-08-26: disclosed

References