Junglewise Threat Intelligence

CVE-2026-57957: Papermark CORS misconfiguration in viewer upload endpoint

CVE-2026-57957 · Severity: medium · CVSS 4.7 · Published 2026-06-29

Executive brief

Papermark, an open-source document sharing platform, contains a security flaw in how it handles web requests from different domains. This vulnerability allows a malicious website to trick a user's browser into performing actions on the Papermark platform as if they were the authorized user. Specifically, an attacker could silently upload unauthorized files into a victim's secure document room, potentially leading to data corruption or the introduction of malicious content.

Technical details

A Cross-Origin Resource Sharing (CORS) misconfiguration exists in the TUS-based viewer file upload endpoint (`/api/file/tus-viewer`) within `pages/api/file/tus-viewer/[[...file]].ts`. The application reflects the 'Origin' header from incoming requests while simultaneously setting 'Access-Control-Allow-Credentials' to true. This combination allows an attacker to host a malicious webpage that, when visited by an authenticated Papermark user, can issue authenticated requests to the victim's session. An attacker can exploit this to upload arbitrary files into a victim's dataroom or read credentialed responses. The vulnerability is present in versions up to and including 0.22.0.

Affected products

  • Papermark Papermark through 0.22.0

Timeline

  • 2026-05-24: disclosed: Initial report via email
  • 2026-06-17: disclosed: Public GitHub issue opened
  • 2026-06-29: advisory: NVD publication date

References