CVE-2025-64487
Last modified
CVE-2025-64487 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getoutline | Outline | < 1.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64487?
How severe is CVE-2025-64487?
How do I fix CVE-2025-64487?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64481Datasette is an open source multi-tool for exploring and pub…2.7
- CVE-2025-64482Tuleap is an Open Source Suite to improve management of soft…4.6
- CVE-2025-64483Wazuh is a security detection, visibility, and compliance op…5.3
- CVE-2025-64484OAuth2-Proxy is an open-source tool that can act as either a…8.5
- CVE-2025-64485CVAT is an open source interactive video and image annotatio…5.3
- CVE-2025-64486calibre is an e-book manager. In versions 8.13.0 and prior, …9.3
- CVE-2025-64488SuiteCRM is an open-source, enterprise-ready Customer Relati…8.8
- CVE-2025-64489SuiteCRM is an open-source, enterprise-ready Customer Relati…8.8
- CVE-2025-6449A vulnerability was found in code-projects Simple Online Hot…9.8
- CVE-2025-64490SuiteCRM is an open-source, enterprise-ready Customer Relati…8.3
- CVE-2025-64491SuiteCRM is an open-source, enterprise-ready Customer Relati…6.1
- CVE-2025-64492SuiteCRM is an open-source, enterprise-ready Customer Relati…8.8
Are you affected by CVE-2025-64487?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
