CVE-2026-105314 PUBLISHED

Assigner: mitre
Reserved: 05.10.2026 Published: 05.10.2026 Updated: 05.10.2026

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor Papermerge
Product Papermerge
Versions Default: unknown
  • Version 3.5.3 is affected

References

Problem Types

  • CWE-24 Path Traversal: '../filedir' CWE