CVE-2026-33193: GHSL-2026-052: Stored Cross-Site Scripting (XSS) via MIME Type Spoofing in Docmost - CVE-2026-33193
Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoofing (GHSL-2026-052). An attacker could exploit this flaw to inject malicious scripts, potentially compromising the security of users and data. Version 0.70.0 contains a patch.
Other sources
Docmost version v0.25.3 is vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoofing (GHSL-2026-052). An attacker could exploit this flaw to inject malicious scripts, potentially compromising the security of users and data.
— GitHub Security Lab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docmostto a version that resolves this vulnerability.Fixed in 0.70.0Patch GHSL-2026-052 - Compensating control
As a compensating measure while upgrading, mitigate stored XSS exposure caused by MIME type spoofing (GHSL-2026-052) by limiting users’ ability to view or render untrusted content in Docmost until the patch in version 0.70.0 is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33193?
CVE-2026-33193 is classified as a high-severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2026-33193?
To fix CVE-2026-33193, upgrade Docmost to version 0.70.0 or later.
What types of attacks can exploit CVE-2026-33193?
CVE-2026-33193 can be exploited through stored cross-site scripting (XSS) attacks.
What versions of Docmost are affected by CVE-2026-33193?
All versions of Docmost prior to 0.70.0 are affected by CVE-2026-33193.
What is MIME type spoofing in the context of CVE-2026-33193?
MIME type spoofing in CVE-2026-33193 refers to the improper handling of content types which allows malicious scripts to be stored and executed.