External risk intelligence

ShowDoc Unrestricted File Upload Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-0520

ShowDoc is a widely used documentation and knowledge-sharing platform typically deployed as a web application. Such systems are commonly hosted on public-facing servers or accessible via web interfaces to facilitate collaboration, making the application's file upload and web management surfaces frequently reachable from the internet.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in ShowDoc, a documentation platform, could allow unauthorized users to execute arbitrary code on affected systems. This is due to an issue with how the application handles file uploads, specifically by not properly validating file extensions.

  • Unrestricted file uploads can lead to code execution.
  • This affects widely used documentation platforms.
  • Confirm relevance and exposure of this documentation tool.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by uploading a malicious file through a publicly accessible ShowDoc instance. This occurs due to insufficient validation of file extensions, allowing an attacker to upload and execute arbitrary PHP code, potentially leading to remote code execution.

  • Publicly accessible web interface.
  • Unrestricted file upload feature.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

Improper file validation in ShowDoc could allow an attacker to upload and execute arbitrary PHP files. This could lead to the compromise of the server where ShowDoc is hosted.

  • Server-side PHP execution.
  • Unrestricted file upload via web interface.
  • Remote code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The ShowDoc platform's unrestricted file upload vulnerability requires attention from application owners and infrastructure teams. The first practical step is to locate all ShowDoc instances, determine their exposure and criticality, identify the accountable owner, and then strategize remediation based on risk assessment.

  • Application owners must manage this issue.
  • Verify ShowDoc deployment reachability.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ShowDoc?

ShowDoc is a web-based documentation and knowledge-sharing platform. Teams use it to create, store, and collaborate on technical documents, API specifications, and project manuals. It is typically deployed as a self-hosted web application that provides a centralized portal for internal or public knowledge management.

What does CWE-434 mean for CVE-2025-0520?

This vulnerability is classified as CWE-434, which is an Unrestricted Upload of File with Dangerous Type. In simple terms, the application fails to verify that a file is a safe document type (like an image or PDF) before saving it. Because it misses this check, an attacker can upload a malicious PHP script instead, which the server then incorrectly treats as a legitimate program to execute.

How does an attacker trigger this vulnerability?

An attacker triggers this by interacting with the application's file upload feature to submit a crafted file. The vulnerability specifically involves bypassing extension validation to place executable PHP code on the server. Importantly, simply browsing or viewing existing documentation does not trigger this; the attacker must have the ability to perform a file upload operation within the application.

Is my ShowDoc instance at risk?

According to Halo Surface Signal, ShowDoc is often deployed on public-facing servers to enable collaboration, which frequently places these interfaces within reach of the internet. If your instance is accessible from the internet, it is at higher risk. You should prioritize checking any instance that is reachable outside your internal network, as these are the primary surfaces attackers target.

What should I do first to manage this risk?

Start by performing an inventory to locate all active ShowDoc instances in your environment. Once identified, confirm the specific version running, as this issue affects versions before 2.8.7. After locating them, verify their network accessibility and identify the owner responsible for the system so you can coordinate a risk assessment and plan for necessary updates.

References