CVE Details

CVE-2021-3199 ONLYOFFICE Docs Server Path Traversal Vulnerability
Published: 2026-10-08 CVSS: 9.8 CRITICAL Product: ONLYOFFICE Docs Due Date: 2026-10-11

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

No GitHub PoC data.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > product n/a
containers > cna > affected > 0 > vendor n/a
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version n/a
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
containers > cna > problemTypes > 0 > descriptions > 0 > description n/a
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type text
containers > cna > providerMetadata > dateUpdated 2022-03-21T20:03:15.000Z
containers > cna > providerMetadata > orgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
containers > cna > providerMetadata > shortName mitre
containers > cna > references > 0 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 0 > url https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563
containers > cna > references > 1 > tags > 0 x_refsource_MISC
containers > cna > references > 1 > url https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py
containers > cna > references > 2 > tags > 0 x_refsource_MISC
containers > cna > references > 2 > url https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py
containers > cna > x_legacyV4Record > CVE_data_meta > ASSIGNER [email protected]
containers > cna > x_legacyV4Record > CVE_data_meta > ID CVE-2021-3199
containers > cna > x_legacyV4Record > CVE_data_meta > STATE PUBLIC
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name n/a
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value n/a
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name n/a
containers > cna > x_legacyV4Record > data_format MITRE
containers > cna > x_legacyV4Record > data_type CVE
containers > cna > x_legacyV4Record > data_version 4.0
containers > cna > x_legacyV4Record > description > description_data > 0 > lang eng
containers > cna > x_legacyV4Record > description > description_data > 0 > value Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang eng
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value n/a
containers > cna > x_legacyV4Record > references > reference_data > 0 > name https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563
containers > cna > x_legacyV4Record > references > reference_data > 0 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 0 > url https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563
containers > cna > x_legacyV4Record > references > reference_data > 1 > name https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py
containers > cna > x_legacyV4Record > references > reference_data > 1 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 1 > url https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py
containers > cna > x_legacyV4Record > references > reference_data > 2 > name https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py
containers > cna > x_legacyV4Record > references > reference_data > 2 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 2 > url https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py
containers > adp > 0 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 0 > providerMetadata > shortName CVE
containers > adp > 0 > providerMetadata > dateUpdated 2024-08-03T16:45:51.411Z
containers > adp > 0 > title CVE Program Container
containers > adp > 0 > references > 0 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 0 > tags > 1 x_transferred
containers > adp > 0 > references > 0 > url https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563
containers > adp > 0 > references > 1 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 1 > tags > 1 x_transferred
containers > adp > 0 > references > 1 > url https://github.com/nola-milkin/poc_exploits/blob/master/CVE-2021-3199/poc_uploadImageFile.py
containers > adp > 0 > references > 2 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 2 > tags > 1 x_transferred
containers > adp > 0 > references > 2 > url https://github.com/moehw/poc_exploits/tree/master/CVE-2021-3199/poc_uploadImageFile.py
containers > adp > 1 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 1 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > adp > 1 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > adp > 1 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 1 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 1 > metrics > 1 > other > type ssvc
containers > adp > 1 > metrics > 1 > other > content > id CVE-2021-3199
containers > adp > 1 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 1 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 1 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 1 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 1 > metrics > 1 > other > content > version 2.0.3
containers > adp > 1 > metrics > 1 > other > content > timestamp 2026-10-08T17:40:14.811565Z
containers > adp > 1 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3199
containers > adp > 1 > references > 0 > tags > 0 government-resource
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > cweId CWE-22
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > description CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
containers > adp > 1 > title CISA ADP Vulnrichment
containers > adp > 1 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 1 > providerMetadata > shortName CISA-ADP
containers > adp > 1 > providerMetadata > dateUpdated 2026-10-08T17:41:47.425Z
cveMetadata > assignerOrgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
cveMetadata > assignerShortName mitre
cveMetadata > cveId CVE-2021-3199
cveMetadata > datePublished 2021-01-22T02:41:34.000Z
cveMetadata > dateReserved 2021-01-21T00:00:00.000Z
cveMetadata > dateUpdated 2026-10-08T17:41:47.425Z
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.2