CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-30187

Critical · CVSS 9.8

ONLYOFFICE DocumentServer — Out-of-bounds write (OOB memory access) leading to Remote Code Execution via crafted JavaScript file

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-787

Description

An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

Search profile — drives PoC discovery

Symbols NativeControlEmbed.cppNativeControlEmbeddoctrendererDesktopEditor/doctrenderer/embedNativeControlEmbed.cpp#L110core/commit/2b6ad83b36afd9845085b536969d366d1d61150a
Keywords CVE-2023-30187ONLYOFFICE DocumentServerout of bounds memory accessarbitrary code executioncrafted JavaScriptdoctrendererNativeControlEmbedONLYOFFICE RCEDocumentServer exploitmerrychap
Versions: 4.0.3 through 7.3.2

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z