Improper Authentication in Documenso's Google OAuth Login Component
CVE-2026-13543
Key Information:
Badges
What is CVE-2026-13543?
A vulnerability discovered in Documenso versions up to 2.11.0 pertains to a flaw in the Google OAuth Login component. This issue resides in the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts, where improper authentication functionality can be exploited. The vulnerability allows a potential attacker to execute a remote attack, characterized by high complexity, thus making exploitation challenging. Although the exploit is now publicly available, a pull request to address this issue is awaiting acceptance.
Affected Version(s)
Documenso 2.0
Documenso 2.1
Documenso 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
