CVE-2025-64487

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*

History

20 Feb 2026, 18:17

Type Values Removed Values Added
CPE cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*
References () https://github.com/outline/outline/releases/tag/v1.1.0 - () https://github.com/outline/outline/releases/tag/v1.1.0 - Release Notes
References () https://github.com/outline/outline/security/advisories/GHSA-c8xf-3j86-7686 - () https://github.com/outline/outline/security/advisories/GHSA-c8xf-3j86-7686 - Vendor Advisory
First Time Getoutline
Getoutline outline

11 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 21:16

Updated : 2026-02-20 18:17


NVD link : CVE-2025-64487

Mitre link : CVE-2025-64487

CVE.ORG link : CVE-2025-64487


JSON object : View

Products Affected

getoutline

  • outline
CWE
CWE-269

Improper Privilege Management