Vulnerability Description
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/AstoKr/papermark/pull/1
- https://github.com/papermark/papermark/issues/2178
- https://www.vulncheck.com/advisories/papermark-cors-misconfiguration-in-viewer-u
FAQ
What is CVE-2026-57957?
CVE-2026-57957 is a vulnerability with a CVSS score of 4.7 (MEDIUM). Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by ex...
How severe is CVE-2026-57957?
CVE-2026-57957 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57957?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.