HKCERT said on 9 October that attackers are exploiting a flaw in ONLYOFFICE Docs, tracked as CVE-2021-3199. It describes a path traversal bug, where a crafted file path reaches folders it should not. The bug appears when the product uses JWT, a signed token apps use to check access. An attacker can add a "/.." sequence to an image upload parameter. HKCERT says this could let a remote attacker run code on the system and bypass security limits. It rates the risk High. The affected software is ONLYOFFICE Document Server before version 5.6.3, and HKCERT advises moving to 5.6.3 or later.
The bulletin leaves several things open. It does not say who is carrying out the attacks, how many systems have been hit, or when the attacks began. It gives no detail on what attackers do after they get in. It lists no workaround other than updating. For its references, it points to the ONLYOFFICE changelog for version 5.6.3 and to the CISA known exploited vulnerabilities catalog.
Teams that run ONLYOFFICE Document Server should check which version they have. Any version older than 5.6.3 falls inside the range HKCERT names, and the flaw is reported as actively exploited.