GHSA-mxgr-89mh-cjg6HighCVSS 8.1

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules,...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

🔗 References (6)