Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API
References
| Link | Resource |
|---|---|
| https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2025-57682 | Third Party Advisory |
| https://github.com/mfts/papermark | Product |
| https://papermark.com/ | Product |
Configurations
History
No history.
Information
Published : 2025-09-22 16:15
Updated : 2025-10-14 19:56
NVD link : CVE-2025-57682
Mitre link : CVE-2025-57682
CVE.ORG link : CVE-2025-57682
JSON object : View
Products Affected
papermark
- papermark
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
