CVE-2025-68663

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*

History

20 Feb 2026, 18:14

Type Values Removed Values Added
References () https://github.com/outline/outline/releases/tag/v1.1.0 - () https://github.com/outline/outline/releases/tag/v1.1.0 - Release Notes
References () https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m - () https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Getoutline
Getoutline outline
CPE cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*

11 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 21:16

Updated : 2026-02-20 18:14


NVD link : CVE-2025-68663

Mitre link : CVE-2025-68663

CVE.ORG link : CVE-2025-68663


JSON object : View

Products Affected

getoutline

  • outline
CWE
CWE-287

Improper Authentication