GHSA-qm54-2jq3-88j9HighCVSS 7.5

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...

Published
August 29, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.

🔗 References (6)