Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
UnratedPublic exploit

Improper Authentication in Documenso Google OAuth Login

IdentifiersCVE-2026-13543CWE-287

CVE-2026-13543 is an improper authentication vulnerability in Documenso affecting versions up to 2.11.0. The issue is reported in the Google OAuth Login component, specifically in the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts. The vulnerable functionality is not further specified in the provided content, but the flaw allows manipulation of the OAuth callback handling logic, resulting in improper authentication. The vulnerability is remotely exploitable, though exploitation is described as high complexity and difficult. Public exploit information is reported to exist. No additional technical details about the exact code path or validation failure are available in the provided material.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation could allow an attacker to bypass or subvert intended authentication controls in Documenso's Google OAuth login flow. Because the issue is categorized as improper authentication, the likely impact is unauthorized access to application accounts or sessions associated with the affected OAuth workflow. The precise scope of access, privilege level obtained, and any downstream effects are not specified in the provided content.

Mitigation

If you can’t patch tonight, do this now.

Until an official fix is deployed, reduce exposure by disabling Google OAuth login if operationally feasible, or restricting its use to trusted users and tightly controlled environments. Monitor authentication logs for anomalous OAuth callback activity and unexpected account sign-ins. If possible, add compensating controls around OAuth callback validation at the application or reverse-proxy layer and require additional authentication factors for sensitive accounts.

Remediation

Patch, then assume compromise.

Upgrade to a fixed Documenso release once an official patch is available. The provided content states that a pull request addressing the issue exists but was awaiting acceptance at the time of reporting. Review the upstream Documenso repository for the fix to packages/auth/server/lib/utils/handle-oauth-callback-url.ts, apply the patch or upgrade to the first release that includes it, and validate the Google OAuth callback handling logic after deployment.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.