CVE-2025-68663

O

utline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.

Configurations

Configuration 1 (hide)

cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*

History

20 Feb 2026, 18:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*
References () https://github.com/outline/outline/releases/tag/v1.1.0 - () https://github.com/outline/outline/releases/tag/v1.1.0 - Release Notes
References () https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m - () https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m - Vendor Advisory
First Time Getoutline
Getoutline outline

12 Feb 2026, 15:10

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 21:16

Updated : 2026-02-20 18:14


NVD link : CVE-2025-68663

Mitre link : CVE-2025-68663

CVE.ORG link : CVE-2025-68663


JSON object : View

Products Affected
CWE
CWE-287

Improper Authentication