CVE-2026-44695

Published
View on NVD ↗
CVSS v3
5.8
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in Outline user complete the callback and link that user's Outline account to the attacker's Slack team_id and user_id. The linked Slack identity can then use the Slack /outline search command as the victim Outline user. This vulnerability is fixed in 1.7.1.

The fastest knowledge base for growing teams. Beautiful, realtime collaborative, feature packed, and markdown compatible.
GitHubGitHub
39.1K