Sceawere
Vulnerability Detail
CVE-2026-105314UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Papermerge Directory Traversal RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 11h ago
- Vendor
- Papermerge
- Product
- Papermerge
- Attack Type
- CWE-24 Path Traversal: '../filedir'
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-05T08:17:15.797Z",
"pubdate": "2026-10-05T08:17:15.797Z",
"executiveSummary": "Papermerge version 3.5.3 is susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from improper input validation during file uploads.\nThe vulnerability is categorized as a directory traversal flaw, which allows an authenticated standard user to write files to arbitrary locations on the host filesystem.\nBy specifically targeting Python's site-packages directory, an attacker can deploy a malicious .pth file, which the Python interpreter automatically executes upon initialization.\nThis vulnerability grants an attacker the ability to achieve persistent, arbitrary code execution with the privileges of the application process.\nSuccessful exploitation requires valid user authentication but does not require administrative privileges, posing a significant risk to the confidentiality, integrity, and availability of the host system.\nThe exploit path leverages the application's document upload API, making it reachable by any user with standard document management permissions.",
"technicalDetails": "The vulnerability resides within the /api/documents/upload endpoint of Papermerge 3.5.3. The application fails to adequately sanitize file paths provided during the upload process, allowing for directory traversal sequences (e.g., ../) in the filename or destination path parameters.\nThe primary attack vector involves an authenticated user crafting a malicious request to the upload API. By manipulating the destination path, the attacker can break out of the intended upload directory and traverse the filesystem to reach sensitive Python configuration directories.\nThe target of choice is the site-packages directory of the Python environment hosting the Papermerge application. Python's site module scans this directory for .pth (path configuration) files upon interpreter startup. When a .pth file is found, the interpreter executes any lines prefixed with 'import ' as Python code.\nThe attack flow follows these steps: 1) The attacker authenticates as a standard user. 2) The attacker initiates an upload request via /api/documents/upload. 3) The attacker injects directory traversal sequences into the upload parameters to point the target location toward the site-packages directory. 4) The attacker uploads a malicious .pth file containing a payload designed to establish a reverse shell or execute arbitrary system commands. 5) Upon the next restart of the Papermerge application or the underlying Python process, the Python interpreter parses the malicious .pth file.\nOnce the .pth file is executed, the malicious code runs with the same permissions as the user executing the Papermerge instance. This leads to full system compromise, allowing the attacker to exfiltrate sensitive data, manipulate documents, or move laterally within the infrastructure.\nThe root cause is an insufficient validation mechanism that does not enforce strict path constraints on user-supplied file names or upload destination paths, failing to prevent traversal beyond the intended data storage directory."
}