GHSA-x43r-25j9-cfc4HighCVSS 7.5

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.

🔗 References (6)