Executive brief
GROWI is a team collaboration and wiki platform. An access control vulnerability in its attachment API allows authenticated users to retrieve metadata about files attached to pages they do not have permission to view. An attacker could use this to discover sensitive documents or attachment information that should be restricted.
Technical details
The vulnerability is an access control bypass (CWE-639) in the GET /_api/v3/attachment/:id endpoint. The endpoint fails to validate whether the authenticated user has permission to access the page associated with a requested attachment. An attacker with valid credentials can enumerate or retrieve attachment metadata by supplying known attachment identifiers, even for pages marked as private or restricted. The vulnerability requires authentication but no special privileges. A fix is available in versions after v8.0.2.
Affected products
- GROWI Labs GROWI before v8.0.3 (v8.0.2 confirmed vulnerable)
Timeline
- 2026-09-01: disclosed