Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Papermerge 3.5.3 contains a critical remote code execution vulnerability in its document upload API endpoint that allows standard users to write arbitrary files outside the intended upload directory. By exploiting directory traversal in the /api/documents/upload call, attackers can place Python .pth files into the site-packages directory—a trusted Python library path. When the Python interpreter restarts, it automatically executes code from these .pth files, granting the attacker persistent code execution. This vulnerability affects any organization running Papermerge 3.5.3, particularly those where document management handles sensitive data or operates in restricted network environments. The attack requires minimal privileges (standard user access) and no authentication bypass, making it an attractive target for both external attackers and malicious insiders.
While this CVE currently maps to CWE-24 (Relative Path Traversal) with no direct MITRE ATT&CK technique assignment, Casky's Claude-powered analysis would correlate this attack pattern with multiple adversarial techniques including Abuse of Functionality (T1648), Exploitation for Privilege Escalation (T1548), and Execution (T1059). Practitioners using Casky would observe findings highlighting the suspicious file write patterns to site-packages directories, the unusual .pth file creation during upload operations, and indicators of interpreter-level code execution. Extended reasoning would connect the dots between seemingly isolated API calls and downstream process execution, revealing the complete attack chain from upload to persistent code execution—a pattern that traditional signature-based detection often misses but that behavioral and contextual analysis excels at identifying.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-105314. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation