FAIL › dossier
document server
PRODUCT· dossier confidence 50%
ONLYOFFICE DocumentServer is a collaborative document platform that suffered two critical remote code execution vulnerabilities in 2023, both exploitable via crafted JavaScript files, highlighting significant risks in its web-based document processing architecture.
PROFILE
CategoryDocument ServerWhat they doONLYOFFICE DocumentServer is a collaborative document editing and management platform.
SECURITY POSTURE
The vendor has a critical vulnerability history involving remote code execution via crafted JavaScript files in the DocumentServer product, indicating potential weaknesses in sandboxing or input validation for web-based document processing.
Notable failures
- CVE-2023-30186 RCE via use-after-free
- CVE-2023-30187 RCE via out-of-bounds memory access
Patterns: critical RCE vulnerabilities in web document processing components
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-08-14 | CVE-2023-30186 | critical | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. |
| 2023-08-14 | CVE-2023-30187 | critical | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. |
Open questions: Are there any other unpatched vulnerabilities in the DocumentServer product? · What is the current patching cadence for ONLYOFFICE DocumentServer?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:16:14.971207+00:00