Impact
A flaw in the Google OAuth login component of Documenso allows manipulation of the callback handling logic, leading to improper authentication. The inability to authenticate properly means that an attacker could potentially adopt an authenticated session without legitimate credentials. This consequence is inferred from the description of improper authentication and is not explicitly confirmed in the CVE text.
Affected Systems
Documenso releases up to and including version 2.11.0 are impacted. The vulnerability resides in the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts, which is used by the Google OAuth integration.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS data is not available and the issue is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not yet occurred. The attack requires remote manipulation of the OAuth callback flow, is described as having high complexity, and is considered difficult to achieve. The exploit is publicly available and may be employed by attackers, but a patch is still pending code review.
OpenCVE Enrichment