Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses. | |
| Title | Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint | |
| First Time appeared |
Papermark
Papermark papermark |
|
| Weaknesses | CWE-942 | |
| CPEs | cpe:2.3:a:papermark:papermark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Papermark
Papermark papermark |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:23:10.419Z
Reserved: 2026-06-26T13:59:33.048Z
Link: CVE-2026-57957
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T20:00:03Z
Weaknesses