CVE-2026-82472
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| documenso | documenso | 0 < 2.13.0 | affected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
References
- https://github.com/documenso/documenso/commit/4f346d3c2d5264f221e4d787e162f16051e44114
- https://github.com/documenso/documenso/blob/v2.12.0/apps/remix/server/api/files/files.ts
- https://github.com/documenso/documenso
- https://www.vulncheck.com/advisories/documenso-before-2.13.0-unauthenticated-file-upload-via-api-files-upload-pdf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.