7.5
CVE-2026-105314
- EPSS 0.9%
- Veröffentlicht 05.10.2026 07:28:30
- Zuletzt bearbeitet 06.10.2026 18:16:43
- Erkennungen
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPapermerge
≫
Produkt
Papermerge
Default Statusunknown
Version
3.5.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.9% | 0.583 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-24 Path Traversal: '../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.
https://github.com/kashishtopi/cve-pocs/blob/main/papermerge-core-arbitrary-file-write-rce/HR-papermerge-core-path-traversal-rce.pdf
https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/features/document/router.py
https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/pathlib.py
https://github.com/kashishtopi/cve-pocs/tree/main/papermerge-core-arbitrary-file-write-rce