CVE-2026-44695

MEDIUM CVSS 3.1: 6.5 EPSS 0.12%
Updated Jun 17, 2026
Getoutline
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 1.7.1
Fixed In 1.7.1
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Getoutline
Public PoC No

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in Outline user complete the callback and link that user's Outline account to the attacker's Slack team_id and user_id.

The linked Slack identity can then use the Slack /outline search command as the victim Outline user. This vulnerability is fixed in 1.7.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Getoutline Outline
cpe:2.3:a:getoutline:outline:*:*:*:*:*:*:*:*
1.7.1