Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API
References
Link | Resource |
---|---|
https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2025-57682 | Third Party Advisory |
https://github.com/mfts/papermark | Product |
https://papermark.com/ | Product |
Configurations
History
14 Oct 2025, 19:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2025-57682 - Third Party Advisory | |
References | () https://github.com/mfts/papermark - Product | |
References | () https://papermark.com/ - Product | |
CPE | cpe:2.3:a:papermark:papermark:*:*:*:*:*:*:*:* | |
First Time |
Papermark
Papermark papermark |
22 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-22 16:15
Updated : 2025-10-14 19:56
NVD link : CVE-2025-57682
Mitre link : CVE-2025-57682
CVE.ORG link : CVE-2025-57682
JSON object : View
Products Affected
papermark
- papermark
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')