Papra是Papra开源的一个文档管理与归档平台。 Papra 26.4.0之前版本存在代码问题漏洞,该漏洞源于Papra webhook系统允许经过身份验证的用户注册任意URL作为webhook端点,且未验证目标地址,可能导致服务器在每个文档事件中向注册的URL(包括localhost、内部网络范围和云提供商元数据端点)发出出站HTTP POST请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35460 | 4.3 MEDIUM | Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name |
| CVE-2026-35462 | 4.3 MEDIUM | Papra Does Not Reject Expired API Keys |
No comments yet