What is ONLYOFFICE Docs?
ONLYOFFICE Docs, previously and still widely known as ONLYOFFICE Document Server, is the server-side component of the ONLYOFFICE office suite. It renders and co-edits Word, Excel, and PowerPoint documents in the browser, and it is the collaborative editing engine embedded in Nextcloud, ownCloud, Seafile, Alfresco, Confluence, Moodle, Zimbra, and a long list of other platforms. Deployments run it as a Docker container or a Linux service alongside the platform it serves. Because it has to receive and convert documents and images uploaded by users, it exposes HTTP endpoints that accept attacker-influenced file content, and it usually sits on an internal network segment with the file storage it edits.
Overview
CVE-2021-3199 is a path traversal in the image upload handling of ONLYOFFICE Document Server. A request to the upload service carries a destination path for the image being saved. The server did not normalise or constrain that path, so a /.. sequence in the parameter walked the attacker out of the intended upload directory and let them write a file anywhere the service account could reach. Writing attacker-controlled bytes to an arbitrary path on a document conversion server is a short step from code execution, which is why NVD scores it 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CISA's entry calls out remote code execution.
The CVE text contains a detail that reads strangely on first pass: the flaw occurs "when JWT is used". ONLYOFFICE signs requests between the host platform and Document Server with a JSON Web Token, and the vulnerable code path is the one behind that signature check. The public proof of concept confirms this, requiring a token that passes isValidJwt and that carries both docId and encrypted claims, with a request body beginning ENCRYPTED; followed by the relative path. In other words JWT is a precondition of reaching the code, not a defence that was bypassed. NVD's vector assumes no privileges are required, which holds where the shared secret is the documented default, is weak, or has leaked from the integrating application's configuration. Where a strong, private secret is in use, an attacker needs that secret first. Treat the privilege requirement as deployment dependent.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| ONLYOFFICE Document Server | 5.1.5 through 5.6.2 | 5.6.3 |
| ONLYOFFICE Docs (all later branches) | not affected | 5.6.3 and later |
The proof-of-concept notes give the affected range as 5.1.5 through 5.6.2; NVD states simply "before 5.6.3". Bundled and embedded copies matter here. If Document Server arrived as part of a Nextcloud, Zimbra, or appliance package, check the version of the editor component itself rather than the host application.
Technical Details
The CWE is CWE-22, improper limitation of a pathname to a restricted directory: the code joins user input onto a base directory and trusts that the result stays underneath it. The fix in the 5.6.3 changelog is recorded as "Fix Path Traversal vulnerability via image upload params" against internal bug 46113, in the uploadImageFile handler in fileuploaderservice.js. The immediately preceding release, 5.6.2, had fixed a sibling traversal through the savefile parameter, so this was the second pass over the same class of bug in the same service.
Attack characteristics: a single HTTP request, no user interaction, no document needs to be open, and no memory corruption or race involved. The attacker needs network reach to the Document Server HTTP port and a token the server accepts. Impact is an arbitrary file write as the Document Server user, which can be turned into execution by dropping a script into a path the server or a neighbouring web server will run, or by overwriting a Node.js file the service loads on restart.
Discovery
Positive Technologies reported the issue, filed in their advisory database as PT-2021-19619 on 2021-01-21, five days before the CVE record was published. ONLYOFFICE fixed it in 5.6.3 and documented it only as a changelog line, with no standalone security bulletin. A public proof of concept, poc_uploadImageFile.py, was later published on GitHub along with a technical readme describing the JWT claims and body format required.
Exploitation Context
CISA added CVE-2021-3199 to the KEV catalog on 2026-10-08, which establishes confirmed exploitation. No public reporting names a threat actor, a campaign, or a ransomware family for this CVE, and CISA records it as not known to be used in ransomware. Working exploit code has been publicly available for years, which lowers the bar for opportunistic use against the unpatched long tail.
Exposure is awkward to count. Document Server is normally deployed as a back-end for another platform rather than as a destination site, so internet-wide scans undercount instances that are reachable only after traversing a reverse proxy. The population that matters is old self-hosted stacks: Nextcloud or similar installations where the editor container was deployed once in 2020 or 2021 and never rebuilt. Note also that ONLYOFFICE components have continued to attract traversal research, including the 2026 Zimbra-bundled ONLYOFFICE issue tracked as CVE-2026-93643, so an aged Document Server is likely to carry more than this one bug.
Remediation
- Upgrade to ONLYOFFICE Docs 5.6.3 at absolute minimum, and in practice to a current supported release. A 5.x Document Server is roughly five years behind and carries many other fixed vulnerabilities.
- If you run it in Docker, pull a fresh image rather than restarting the existing container; a long-lived container keeps the vulnerable code even after the host is updated.
- Rotate the JWT secret. Set
JWT_ENABLEDwith a long randomJWT_SECRETand make sure the same value is configured in the integrating application. Any deployment still running the documented default secret should treat it as public. - Isolate the service. Document Server should not be reachable from the internet directly; restrict its port to the application servers that integrate with it, using a firewall rule or a reverse proxy with an allowlist.
- If you cannot patch immediately, review the service account's filesystem permissions and remove write access to anything outside the cache and upload directories it genuinely needs.
- Review for compromise. Look in the web and proxy logs for upload requests containing
..sequences, and check the Document Server filesystem and any shared document storage for unexpected script files, modified.jsfiles under the application directory, and files whose timestamps predate your last deployment. - Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and perform the forensic triage the directive requires.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2021-3199 |
| Vendor / Product | ONLYOFFICE — Docs |
| NVD Published | 2021-01-26 |
| NVD Last Modified | 2026-10-08 |
| CVSS 3.1 Score | 9.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-22 find similar ↗ |
| CISA KEV Added | 2026-10-08 |
| CISA KEV Deadline | 2026-10-11 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2021-01-21 | Positive Technologies files advisory PT-2021-19619 describing directory traversal with code execution in the Document Server upload path |
| 2021-01-26 | CVE-2021-3199 record published |
| 2026-10-08 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2026-10-11 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2021-3199 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| ONLYOFFICE DocumentServer Changelog 5.6.3 - Fix Path Traversal Vulnerability via Image Upload Params | Vendor Advisory |
| Public Proof of Concept - poc_uploadImageFile.py and Technical Notes | Exploit/PoC |
| Positive Technologies PT-2021-19619 - ONLYOFFICE Document Server Directory Traversal | Security Research |
| OSV - CVE-2021-3199 | Vulnerability Database |
| CIRCL Vulnerability Lookup - CVE-2021-3199 | Vulnerability Database |