CVE-2026-105314: High severity Papermerge Papermerge vulnerability
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs standard authenticated user privileges. No user interaction is required, and exploitation is performed remotely through the document upload API.
When does the injected code run?
The upload can write a Python .pth file into site-packages using directory traversal. Code in that file executes the next time the Python interpreter starts, so execution may not be immediate until a relevant restart occurs.
Are systems exposed by default?
The available information identifies Papermerge 3.5.3 and the /api/documents/upload endpoint, but does not state whether the vulnerable behavior is enabled or reachable in a default deployment.
How can defenders assess potential impact before patching?
Review authenticated document-upload activity for directory-traversal payloads and inspect Python site-packages locations for unexpected .pth files. Investigate interpreter or application restarts following suspicious uploads, since those restarts can trigger execution.