PatchSiren

Documenso CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Documenso CVE published 2026-06-29

CVE-2026-13543

CVE-2026-13543 is a vulnerability detected in Documenso up to version 2.11.0. The vulnerability affects an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts in the Google OAuth Login component. The manipulation leads to improper authentication, and the attack can be launched remotely with high complexity. The exploitation appears to be difficult, but the exploit [truncated]