Impact
Papermerge 3.5.3 allows a standard user to execute arbitrary code remotely by exploiting directory traversal in the /api/documents/upload endpoint. By providing a specially crafted path, an attacker can write a .pth file into the site‑packages directory; that file is executed automatically when the Python interpreter starts again. This grants the attacker full privilege to run any code on the host, effectively compromising confidentiality, integrity, and availability of the system.
Affected Systems
Vulnerable in Papermerge version 3.5.3, the open‑source Document Management application maintained by Papermerge. No other versions or variants were listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity with potential for remote code execution. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at present. The attack vector is inferred to be remote, via the public API, requiring only normal user credentials to upload a malicious file. Successful exploitation would allow the requester to run arbitrary code with the privileges of the application process after the next interpreter restart.
OpenCVE Enrichment