Executive brief
Ascertia SigningHub, a platform used for digital signatures and document workflows, contains a critical vulnerability in its file upload system. An attacker can upload a specially crafted file that allows them to execute malicious code on the server. This could lead to a total compromise of the system, including the theft of sensitive documents, disruption of signing services, and unauthorized access to customer data.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Ascertia SigningHub v8.6.8 and earlier. The flaw is located within the file upload component, where the application fails to properly validate or sanitize uploaded files before processing. While some reports suggest the vulnerability involves social engineering via malicious links in converted PDFs, the primary critical-rated advisory indicates that an attacker can achieve remote code execution (RCE) by uploading a crafted file. The attack is reachable over the network and, according to CISA-ADP metrics, does not require prior authentication or user interaction. Users should upgrade to versions later than 8.6.8 to mitigate this risk.
Affected products
- Ascertia SigningHub <= 8.6.8
Timeline
- 2025-10-17: disclosed: Initial CVE publication
- 2025-10-17: advisory: NVD record published