๐Ÿ” CVE Alert

CVE-2026-57957

MEDIUM 4.7

Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.

CWE CWE-942
Vendor papermark
Product papermark
Published Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for papermark papermark

Be the first to know when new medium vulnerabilities affecting papermark papermark are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

papermark / papermark
0 โ‰ค 0.22.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/papermark/papermark/issues/2178 github.com: https://github.com/AstoKr/papermark/pull/1 vulncheck.com: https://www.vulncheck.com/advisories/papermark-cors-misconfiguration-in-viewer-upload-endpoint

Credits

George Chen