CVE-2026-71247: Documenso
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here.
Affected products
- Documenso Documenso: version 0 only
Published 2026-08-05. Last modified 2026-08-26.