Executive brief
Papra, a document management and archiving platform, contains a security flaw that allows users to modify or delete data belonging to other organizations. An authenticated user can rename or delete document tags in a different tenant's account if they know the specific ID of that tag. While this does not allow an attacker to read private documents, it can lead to data corruption and the removal of organizational labels used for document tracking.
Technical details
An authorization bypass (CWE-639) exists in Papra's tag management endpoints due to insufficient server-side validation. While the route handler checks if the authenticated user belongs to the organization ID provided in the URL, the underlying database repository performs update and delete operations using only the tag ID. This allows a cross-tenant write where an attacker can modify or delete tags in a foreign organization by supplying their own organization ID in the URL but a victim's tag ID in the request. Exploitation requires the attacker to know the target tag's 24-character cuid2 ID, which limits the feasibility of brute-force attacks. The vulnerability affects the PUT and DELETE methods for the /api/organizations/:organizationId/tags/:tagId endpoint and is resolved in version 26.5.0.
Affected products
- papra-hq Papra < 26.5.0
Timeline
- 2026-05-05: patched: Fix committed to main branch
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-07-27: disclosed: CVE published to NVD