Impact
OpenSign through version 2.41.3 fails to validate the identity of the caller when one‑time‑password verification is disabled. Attackers can submit a document identifier from a guest signing link to retrieve full document details, including signers, sender identity, and valid download tokens, without authentication. This results in sensitive data exposure and undermines the confidentiality of signed agreements.
Affected Systems
OpenSign by OpenSignLabs, versions up to and including 2.41.3. The issue affects the getDocument cloud function exposed by the OpenSign Server component.
Risk and Exploitability
The CVSS score of 8.7 indicates a high impact vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed remotely through the getDocument endpoint, provided that the system has OTP verification disabled; the attacker only needs to know a valid document ID from a guest signing link. Although the exploitation probability is low, the potential loss of sensitive contractual data warrants prompt attention.
OpenCVE Enrichment