Papermark through 0.22.0 contains a cross-origin resource...
Low severity
Unreviewed
Published
Jun 29, 2026
to the GitHub Advisory Database
•
Updated Jun 29, 2026
Description
Published by the National Vulnerability Database
Jun 29, 2026
Published to the GitHub Advisory Database
Jun 29, 2026
Last updated
Jun 29, 2026
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.
References