Impact
Documenso before version 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring any authentication, session tokens, or API credentials. This flaw allows any remote actor to submit arbitrary PDF files. While the content is not executable, repeated uploads can fill the server’s storage and create thousands of orphaned document records in the database, which in turn can lead to a denial‑of‑service by exhausting disk space or database capacity.
Affected Systems
All installations of Documenso with a version older than 2.13.0 are impacted. The vulnerability resides in the core application and affects any deployment that exposes the upload‑pdf API endpoint without an additional authentication layer.
Risk and Exploitability
The flaw has a CVSS base score of 8.7, denoting high severity, and no EPSS data is currently available. The vulnerability is not listed in the CISA KEV catalog. Because authentication is not required, an attacker can exploit the issue from any network location that can reach the API, making it a high‑risk vector for untrusted networks.
OpenCVE Enrichment