External risk intelligence

ONLYOFFICE Document Server Directory Traversal Leading to Remote Code Execution.

CVE advisoryKnown Exploit

CVE-2021-3199

ONLYOFFICE Document Server is a web-based collaboration application designed to be accessed over the network to provide document editing services. Because it functions as a web application and API service frequently deployed to facilitate remote document processing, the vulnerable endpoint is commonly reachable in internet-facing or edge-service deployment patterns.

Path Traversal

Onlyoffice Document Server

before 5.6.3

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A directory traversal vulnerability in ONLYOFFICE Document Server could allow an unauthenticated attacker to execute arbitrary code on the server. This is due to a flaw in the image upload functionality when JSON Web Token (JWT) is enabled, which could be exploited by manipulating an image upload parameter to traverse directories. The main concern is confirming relevance and exposure given the potential for critical impact.

  • Allows code execution via file uploads.
  • Critical vulnerability, remotely exploitable without authentication.
  • Confirm system relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests to the image upload feature. This feature, located at `/upload`, is exposed externally and does not require authentication. By manipulating an image upload parameter with a directory traversal sequence, an attacker can trick the server into writing files to arbitrary locations, potentially leading to remote code execution.

  • Accessible over the network.
  • Directory traversal via image upload parameter.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

Directory traversal with remote code execution could affect the integrity and availability of the ONLYOFFICE Document Server when JWT is enabled and an attacker can control image upload parameters. This could lead to unauthorized code execution on the server.

  • Server code execution.
  • Malicious file upload.
  • Unauthorized server control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Attackers can exploit this critical vulnerability remotely through a directory traversal flaw in the image upload functionality of ONLYOFFICE Document Server when JWT is enabled. Technical leaders should direct their security and infrastructure teams to identify all instances of ONLYOFFICE Document Server, assess their network exposure and business criticality, and confirm ownership. Subsequently, a risk-based remediation plan, potentially involving vendor coordination or temporary controls, should be developed and executed.

  • Document Server owners should lead remediation efforts.
  • Verify internet-facing and critical deployments first.
  • Plan vendor-coordinated updates or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ONLYOFFICE Document Server?

It is a web-based collaboration suite that enables users to edit, view, and co-author office documents directly within a browser or integrated applications. Organizations typically deploy this server to provide centralized document processing services and API capabilities, often making it a core component of their internal or shared content management infrastructure.

What does directory traversal mean in the context of CVE-2021-3199?

This vulnerability is classified as CWE-22, which describes a path traversal weakness. It occurs when an application fails to properly sanitize user input, allowing an attacker to navigate outside the intended folder structure. In this specific case, an attacker can manipulate an image upload parameter to save malicious files in restricted locations, ultimately enabling unauthorized remote code execution on the server.

How is this vulnerability triggered?

An attacker triggers the vulnerability by sending a specially crafted request to the server's image upload endpoint, specifically using a path traversal sequence. The vulnerability is active when JSON Web Token (JWT) authentication is enabled. It is important to note that if the image upload functionality is disabled or the specific vulnerable endpoint is not reachable by the attacker, this trigger path is not available.

Is my server at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because ONLYOFFICE Document Server is designed for network-based document collaboration, it is frequently deployed in internet-facing or edge-service patterns. This exposure makes the vulnerable /upload endpoint more likely to be reachable by external actors. You should prioritize checking any instance of the software that is accessible over the network.

What are the first steps to address CVE-2021-3199?

Start by identifying all instances of ONLYOFFICE Document Server within your environment and confirming who owns each deployment. Verify the version in use; those older than 5.6.3 are affected. Focus your immediate assessment on servers that are internet-facing or support critical business operations, and coordinate with your infrastructure team to plan and implement necessary updates or temporary security controls.

References