Skip to content
COOEY

FAIL › dossier

document server

PRODUCT

· dossier confidence 50%

ONLYOFFICE DocumentServer is a collaborative document platform that suffered two critical remote code execution vulnerabilities in 2023, both exploitable via crafted JavaScript files, highlighting significant risks in its web-based document processing architecture.

PROFILE
CategoryDocument ServerWhat they doONLYOFFICE DocumentServer is a collaborative document editing and management platform.
SECURITY POSTURE

The vendor has a critical vulnerability history involving remote code execution via crafted JavaScript files in the DocumentServer product, indicating potential weaknesses in sandboxing or input validation for web-based document processing.

Notable failures
  • CVE-2023-30186 RCE via use-after-free
  • CVE-2023-30187 RCE via out-of-bounds memory access
Patterns: critical RCE vulnerabilities in web document processing components
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2023-08-14 CVE-2023-30186 critical A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
2023-08-14 CVE-2023-30187 critical An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
Open questions: Are there any other unpatched vulnerabilities in the DocumentServer product? · What is the current patching cadence for ONLYOFFICE DocumentServer?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:16:14.971207+00:00