CVE Explorer
CVE-2025-68663
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"outline","vendor":"outline","versions":[{"status":"affected","version":"< 1.1.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:734716a2e69f713862f72958c152fef48def37b850b51d642f98bfb7d1581dda · sha256:47c5ebccba910f93… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:734716a2e69f713862f72958c152fef48def37b850b51d642f98bfb7d1581dda · sha256:47c5ebccba910f93… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:734716a2e69f713862f72958c152fef48def37b850b51d642f98bfb7d1581dda · sha256:47c5ebccba910f93… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/outline/outline/releases/tag/v1.1.0","tags":["x_refsource_MISC"],"url":"https://github.com/outline/outline/releases/tag/v1.1.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:734716a2e69f713862f72958c152fef48def37b850b51d642f98bfb7d1581dda · sha256:47c5ebccba910f93… · /containers/cna/references/1
{"name":"https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/outline/outline/security/advisories/GHSA-mx2c-3g2x-5m9m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:734716a2e69f713862f72958c152fef48def37b850b51d642f98bfb7d1581dda · sha256:47c5ebccba910f93… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.