CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-30186

Critical · CVSS 9.8

ONLYOFFICE DocumentServer — Use After Free (UAF) Remote Code Execution via crafted JavaScript

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-416

Description

A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

Search profile — drives PoC discovery

Symbols NativeControlEmbed.cppNativeControlEmbeddoctrendererDesktopEditor/doctrendererDesktopEditor/doctrenderer/embedNativeControlEmbed.cpp#L1102b6ad83b36afd9845085b536969d366d1d61150a
Keywords CVE-2023-30186ONLYOFFICE DocumentServer use after freeONLYOFFICE UAF RCEONLYOFFICE DocumentServer JavaScript exploitNativeControlEmbed use after freedoctrenderer exploitONLYOFFICE 7.3.2 vulnerabilitymerrychap ONLYOFFICE
Versions: 4.0.3 through 7.3.2

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z