PatchSiren

Papermerge CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Papermerge CVE published 2026-10-05

CVE-2026-105314

CVE-2026-105314 is a high-severity vulnerability in Papermerge 3.5.3 that allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter. This vulnerability can lead to unauthorized access and control of the system, potentially resulting in da [truncated]