Executive brief
Papermark, an open-source document sharing platform, contains a security flaw in how it handles web requests from different domains. This vulnerability allows a malicious website to trick a user's browser into performing actions on the Papermark platform as if they were the authorized user. Specifically, an attacker could silently upload unauthorized files into a victim's secure document room, potentially leading to data corruption or the introduction of malicious content.
Technical details
A Cross-Origin Resource Sharing (CORS) misconfiguration exists in the TUS-based viewer file upload endpoint (`/api/file/tus-viewer`) within `pages/api/file/tus-viewer/[[...file]].ts`. The application reflects the 'Origin' header from incoming requests while simultaneously setting 'Access-Control-Allow-Credentials' to true. This combination allows an attacker to host a malicious webpage that, when visited by an authenticated Papermark user, can issue authenticated requests to the victim's session. An attacker can exploit this to upload arbitrary files into a victim's dataroom or read credentialed responses. The vulnerability is present in versions up to and including 0.22.0.
Affected products
- Papermark Papermark through 0.22.0
Timeline
- 2026-05-24: disclosed: Initial report via email
- 2026-06-17: disclosed: Public GitHub issue opened
- 2026-06-29: advisory: NVD publication date