Docs vulnerability

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

Published 16 Sep 2026Updated 19 Sep 20265 sources
CVSS 7.6

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.