PatchSiren cyber security CVE debrief
CVE-2026-105314 Papermerge CVE debrief
CVE-2026-105314 is a high-severity vulnerability in Papermerge 3.5.3 that allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. This vulnerability can lead to unauthorized access and control of the system, potentially resulting in data breaches or system compromise. Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows remote code execution. The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and
- Vendor
- Papermerge
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for Papermerge instances, particularly those with standard user access, should assess exposure and potential impact. They should verify exposure by checking if the Papermerge instance is vulnerable to directory traversal attacks and assess potential impact by evaluating the privileges of standard users. Additionally, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor
Why it matters
CVE-2026-105314 is a high-severity vulnerability in Papermerge 3.5.3 that allows remote code execution by a standard user via directory traversal. Defenders should prioritize verifying exposure and assessing potential impact.
- Remote code execution can lead to unauthorized access and control of the system
- Standard users can exploit the vulnerability, potentially leading to lateral movement
- The vulnerability can be used to execute arbitrary code, potentially leading to data breaches or system compromise
- Verification of exposure and impact is necessary to prioritize remediation efforts
Technical summary
The vulnerability allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. This can lead to unauthorized access and control of the system, potentially resulting in data breaches or system compromise. The vulnerability can be used to execute arbitrary code, potentially leading to lateral movement and system compromise. Defenders should prioritize verifying exposure and assessing potential impact.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows remote code execution.
Recommended defensive actions
- Verify exposure by checking if the Papermerge instance is vulnerable to directory traversal attacks
- Assess potential impact by evaluating the privileges of standard users
- Implement compensating controls, such as restricting access to the /api/documents/upload endpoint
- Monitor for suspicious activity and exception tracking
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is limited. The vulnerability allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. Defenders should verify exposure by checking if the Papermerge instance is vulnerable to directory traversal attacks and assess potential impact by
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105314 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105314
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105314 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105314
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kashishtopi/cve-pocs/blob/main/papermerge-core-arbitrary-file-write-rce/HR-papermerge-core-path-traversal-rce.pdf
-
Source reference
Unverified legacy reference
URL: https://github.com/kashishtopi/cve-pocs/tree/main/papermerge-core-arbitrary-file-write-rce
-
Source reference
Unverified legacy reference
URL: https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/features/document/router.py
-
Source reference
Unverified legacy reference
URL: https://github.com/papermerge/papermerge-core/blob/master/papermerge/core/pathlib.py
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.