{
  "id": 13169566,
  "title": "CVE-2026-100727: unauthenticated file read in GROWI's local upload mode",
  "url": "https://urgent.news/2026/10/09/cve-2026-100727-unauthenticated-file-read-in-growis-local-upload-mode",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T17:40:40.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/stark_zhuang_df5076f35c68/cve-2026-100727-unauthenticated-file-read-in-growis-local-upload-mode-leg"
  },
  "original_language": "en",
  "account": "On October 5, 2026, GROWI, Inc. released version 7.5.5 to address CVE-2026-100727, an unauthenticated file read vulnerability in GROWI's local upload mode. This security flaw allows an unauthorized visitor to access files stored by the platform on the local file system, impacting deployments that store uploads locally. The vulnerability, rated with a base score of 6.9 (CVSS 4.0) and 5.3 (CVSS 3.0), is classified under CWE-552 as files or directories accessible to external parties.\n\nThe exploit is possible when GROWI runs a version lower than 7.5.5 and the file upload setting is configured as \"Local.\" The attack involves an unauthenticated attacker requesting files from non-public pages, which the application serves back upon receiving the request. The impact is limited to confidentiality, as the attacker cannot write or execute files or maintain an authenticated session.\n\nTo remediate the issue, GROWI users must update to version 7.5.5 and verify that attachment settings are correctly configured after the upgrade. For those unable to upgrade immediately, moving uploads to an external storage backend can mitigate the vulnerability. Following the patch, it is essential to review non-public pages with attached files from the exposure window and rotate any related credentials or tokens.",
  "summary": "CVE-2026-100727: unauthenticated file read in GROWI's local upload mode GROWI, the wiki and collaboration platform published by GROWI, Inc., received a security fix in version 7.5.5 on October 5, 2026. The release closes CVE-2026-100727, an access-control defect that lets an unauthenticated visitor read files kept by pages the platform does not expose publicly. The defect applies to deployments…",
  "key_points": [
    "GROWI releases version 7.5.5 to fix CVE-2026-100727 vulnerability.",
    "Unauthenticated attacker can read local files via unpatched GROWI installations.",
    "Upgrading to 7.5.5 or using external storage mitigates confidentiality risk."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}