CVE-2026-71247

Source
https://cve.org/CVERecord?id=CVE-2026-71247
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71247.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71247
Published
2026-08-05T10:56:59Z
Modified
2026-08-28T11:30:17Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Documenso - Assistant Recipient Can Forge Another Signer's Signature in Sequential-Signing Documents
Details

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2 signing path (sign-envelope-field.ts) explicitly blocks assistants from completing SIGNATURE fields, and the project's own test suite comments confirm this guard is absent from the V1 path used here.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71247.json"
}
References

Affected packages

Git / github.com/documenso/documenso

Affected ranges

Type
GIT
Repo
https://github.com/documenso/documenso
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
0
before-prettier
0.*
0.9-developer-preview
v0.*
v0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71247.json"