VYPR

Papermark

by Papermark

CVEs (2)

  • CVE-2025-57682MedSep 22, 2025
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API

  • CVE-2026-57957MedJun 29, 2026
    risk 0.00cvss 4.7epss 0.00

    Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request…