PT-2025-38726 · Papermark · Papermark
Published
2025-09-22
·
Updated
2025-10-14
·
CVE-2025-57682
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Papermark versions prior to 0.20.0
Description
An issue exists in Papermark that allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution. This is possible via the 'POST /api/file/s3/get-presigned-get-url-proxy' API endpoint. The vulnerability involves directory traversal, enabling unauthorized access to files.
Recommendations
Update Papermark to version 0.20.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Papermark