CVE-2026-105314

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.

24

Path Traversal: '../filedir'

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Files Or Directories Modify Files Or Directories
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/kashishtopi/cve-pocs/blob/main/papermerge-core-arbitrary-fil…
https://github.com/kashishtopi/cve-pocs/tree/main/papermerge-core-arbitrary-fil…
https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/featu…
https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/pathl…