The CVE-2026-71247 vulnerability affects Documenso's document-signing UI, specifically the sign-field-with-token.ts handler. This handler allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE r [truncated]
CVE-2026-13543 is a vulnerability detected in Documenso up to version 2.11.0. The vulnerability affects an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts in the Google OAuth Login component. The manipulation leads to improper authentication, and the attack can be launched remotely with high complexity. The exploitation appears to be difficult, but the exploit [truncated]