Published: 2026/10/05  Last Updated: 2026/10/05

Information from GROWI, Inc.

Vulnerability ID:JVN#24352487
Title:GROWI vulnerable to improper access control
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

■Overview
Multiple vulnerabilities have been discovered in GROWI, a system provided by our company.
- Improper Access Control vulnerability
- Cross-Site Scripting vulnerability

■How to Check Affected Products
The affected product is as follows.
Product name: GROWI
Affected versions:
- All versions prior to GROWI v7.5.5

Conditions for being affected:
- When the file upload method is set to "Local"
(Not affected if using Amazon S3 / GCS / Azure Blob Storage)

■Description
When the file upload method is set to "Local," uploaded attachment files were stored in the application's static file serving directory. This allowed direct access to the files without going through the proper delivery paths (/attachment/:id, /download/:id) that perform authorization checks and apply response headers.

■Impact
1. An unauthenticated third party may be able to directly access attachment files on private pages, user profile images, page bulk export files, and audit log export files.
2. Because the Content-Disposition and Content-Security-Policy headers applied through the proper delivery paths are not applied, HTML files may be rendered inline, potentially allowing execution of arbitrary scripts.

■Solution
Update GROWI to v7.5.5 or later.

■Where to Obtain the Fixed Version
[GitHub](https://github.com/growilabs/growi)
[Docker Hub](https://hub.docker.com/r/growilabs/growi/)