CVE-2026-105314: High severity Papermerge Papermerge vulnerability

Published Oct 5, 2026
·
Updated

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

Affected Software

1 affected component
Papermerge Papermerge=3.5.3

Event History

Oct 5, 2026
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker needs standard authenticated user privileges. No user interaction is required, and exploitation is performed remotely through the document upload API.

2

When does the injected code run?

The upload can write a Python .pth file into site-packages using directory traversal. Code in that file executes the next time the Python interpreter starts, so execution may not be immediate until a relevant restart occurs.

3

Are systems exposed by default?

The available information identifies Papermerge 3.5.3 and the /api/documents/upload endpoint, but does not state whether the vulnerable behavior is enabled or reachable in a default deployment.

4

How can defenders assess potential impact before patching?

Review authenticated document-upload activity for directory-traversal payloads and inspect Python site-packages locations for unexpected .pth files. Investigate interpreter or application restarts following suspicious uploads, since those restarts can trigger execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203