CVE-2025-58351 is a medium-severity vulnerability affecting Outline versions 0.72.0 through 0.83.0, specifically when using local file system storage on the same domain as the application. This flaw allows for a Content Security Policy (CSP) bypass and Content-Type bypass. An authenticated attacker can upload a malicious file attachment, leading to script execution within another user's session. While the CVSS score is 6.8, indicating a medium risk, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.72.0, < 0.84.0CPE matchmatch criteria | cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.