CVE-2021-3199 — ONLYOFFICE Docs Server Path Traversal Vulnerability

CVE-2021-3199

ONLYOFFICE Document Server - Path Traversal to RCE via the Image Upload Service

What is ONLYOFFICE Docs?

ONLYOFFICE Docs, previously and still widely known as ONLYOFFICE Document Server, is the server-side component of the ONLYOFFICE office suite. It renders and co-edits Word, Excel, and PowerPoint documents in the browser, and it is the collaborative editing engine embedded in Nextcloud, ownCloud, Seafile, Alfresco, Confluence, Moodle, Zimbra, and a long list of other platforms. Deployments run it as a Docker container or a Linux service alongside the platform it serves. Because it has to receive and convert documents and images uploaded by users, it exposes HTTP endpoints that accept attacker-influenced file content, and it usually sits on an internal network segment with the file storage it edits.

Overview

CVE-2021-3199 is a path traversal in the image upload handling of ONLYOFFICE Document Server. A request to the upload service carries a destination path for the image being saved. The server did not normalise or constrain that path, so a /.. sequence in the parameter walked the attacker out of the intended upload directory and let them write a file anywhere the service account could reach. Writing attacker-controlled bytes to an arbitrary path on a document conversion server is a short step from code execution, which is why NVD scores it 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CISA's entry calls out remote code execution.

The CVE text contains a detail that reads strangely on first pass: the flaw occurs "when JWT is used". ONLYOFFICE signs requests between the host platform and Document Server with a JSON Web Token, and the vulnerable code path is the one behind that signature check. The public proof of concept confirms this, requiring a token that passes isValidJwt and that carries both docId and encrypted claims, with a request body beginning ENCRYPTED; followed by the relative path. In other words JWT is a precondition of reaching the code, not a defence that was bypassed. NVD's vector assumes no privileges are required, which holds where the shared secret is the documented default, is weak, or has leaked from the integrating application's configuration. Where a strong, private secret is in use, an attacker needs that secret first. Treat the privilege requirement as deployment dependent.

Affected Versions

Product Vulnerable Fixed
ONLYOFFICE Document Server 5.1.5 through 5.6.2 5.6.3
ONLYOFFICE Docs (all later branches) not affected 5.6.3 and later

The proof-of-concept notes give the affected range as 5.1.5 through 5.6.2; NVD states simply "before 5.6.3". Bundled and embedded copies matter here. If Document Server arrived as part of a Nextcloud, Zimbra, or appliance package, check the version of the editor component itself rather than the host application.

Technical Details

The CWE is CWE-22, improper limitation of a pathname to a restricted directory: the code joins user input onto a base directory and trusts that the result stays underneath it. The fix in the 5.6.3 changelog is recorded as "Fix Path Traversal vulnerability via image upload params" against internal bug 46113, in the uploadImageFile handler in fileuploaderservice.js. The immediately preceding release, 5.6.2, had fixed a sibling traversal through the savefile parameter, so this was the second pass over the same class of bug in the same service.

Attack characteristics: a single HTTP request, no user interaction, no document needs to be open, and no memory corruption or race involved. The attacker needs network reach to the Document Server HTTP port and a token the server accepts. Impact is an arbitrary file write as the Document Server user, which can be turned into execution by dropping a script into a path the server or a neighbouring web server will run, or by overwriting a Node.js file the service loads on restart.

Discovery

Positive Technologies reported the issue, filed in their advisory database as PT-2021-19619 on 2021-01-21, five days before the CVE record was published. ONLYOFFICE fixed it in 5.6.3 and documented it only as a changelog line, with no standalone security bulletin. A public proof of concept, poc_uploadImageFile.py, was later published on GitHub along with a technical readme describing the JWT claims and body format required.

Exploitation Context

CISA added CVE-2021-3199 to the KEV catalog on 2026-10-08, which establishes confirmed exploitation. No public reporting names a threat actor, a campaign, or a ransomware family for this CVE, and CISA records it as not known to be used in ransomware. Working exploit code has been publicly available for years, which lowers the bar for opportunistic use against the unpatched long tail.

Exposure is awkward to count. Document Server is normally deployed as a back-end for another platform rather than as a destination site, so internet-wide scans undercount instances that are reachable only after traversing a reverse proxy. The population that matters is old self-hosted stacks: Nextcloud or similar installations where the editor container was deployed once in 2020 or 2021 and never rebuilt. Note also that ONLYOFFICE components have continued to attract traversal research, including the 2026 Zimbra-bundled ONLYOFFICE issue tracked as CVE-2026-93643, so an aged Document Server is likely to carry more than this one bug.

Remediation

  1. Upgrade to ONLYOFFICE Docs 5.6.3 at absolute minimum, and in practice to a current supported release. A 5.x Document Server is roughly five years behind and carries many other fixed vulnerabilities.
  2. If you run it in Docker, pull a fresh image rather than restarting the existing container; a long-lived container keeps the vulnerable code even after the host is updated.
  3. Rotate the JWT secret. Set JWT_ENABLED with a long random JWT_SECRET and make sure the same value is configured in the integrating application. Any deployment still running the documented default secret should treat it as public.
  4. Isolate the service. Document Server should not be reachable from the internet directly; restrict its port to the application servers that integrate with it, using a firewall rule or a reverse proxy with an allowlist.
  5. If you cannot patch immediately, review the service account's filesystem permissions and remove write access to anything outside the cache and upload directories it genuinely needs.
  6. Review for compromise. Look in the web and proxy logs for upload requests containing .. sequences, and check the Document Server filesystem and any shared document storage for unexpected script files, modified .js files under the application directory, and files whose timestamps predate your last deployment.
  7. Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and perform the forensic triage the directive requires.

Key Details

PropertyValue
CVE ID CVE-2021-3199
Vendor / Product ONLYOFFICE — Docs
NVD Published2021-01-26
NVD Last Modified2026-10-08
CVSS 3.1 Score9.8
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-22 find similar ↗
CISA KEV Added2026-10-08
CISA KEV Deadline2026-10-11
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-10-11. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2021-01-21Positive Technologies files advisory PT-2021-19619 describing directory traversal with code execution in the Document Server upload path
2021-01-26CVE-2021-3199 record published
2026-10-08Added to CISA Known Exploited Vulnerabilities catalog
2026-10-11CISA BOD 26-04 remediation deadline