No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary File Write Leading to Remote Code Execution via Directory Traversal in Papermerge |
Mon, 05 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. | |
| First Time appeared |
Papermerge
Papermerge papermerge |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:papermerge:papermerge:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Papermerge
Papermerge papermerge |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-06T17:41:46.323Z
Reserved: 2026-10-05T07:28:29.666Z
Link: CVE-2026-105314
Updated: 2026-10-06T16:58:58.209Z
Status : Deferred
Published: 2026-10-05T08:17:15.797
Modified: 2026-10-06T18:16:43.707
Link: CVE-2026-105314
No data.
OpenCVE Enrichment
Updated: 2026-10-05T09:30:10Z