Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields… (CVE-2026-71247)
Documenso's sign-field-with-token.ts component in the live document-signing UI allows a recipient with the ASSISTANT role to fetch and complete fields of any later-or-equal-order recipient in the same envelope without proper restrictions. This includes the ability to upsert signature records for fields not owned by the acting recipient, enabling an assistant to forge another signer's signature in sequential-signing documents. A newer signing path (sign-envelope-field.ts) mitigates this by blocking assistants from completing signature fields, but this protection is absent in the vulnerable V1 path.
AI Analysis
Technical Summary
The vulnerability in Documenso's sign-field-with-token.ts arises because the handler permits recipients with the ASSISTANT role to fetch and complete fields belonging to any recipient with a later or equal signing order in the same envelope, without verifying that the field type is a signature or that the acting recipient owns the field. This lack of access control allows an assistant to forge signature fields of other signers in sequential signing workflows. The project's newer V2 signing path explicitly prevents assistants from completing signature fields, but this safeguard is missing in the V1 path, making it vulnerable to signature forgery attacks.
Potential Impact
An attacker with the ASSISTANT role can forge signature fields of other recipients in the same envelope, compromising the integrity of the document signing process. This can lead to unauthorized completion of signature fields, potentially invalidating the trustworthiness of signed documents. The vulnerability does not affect confidentiality or availability but impacts the integrity of signatures.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Since the newer V2 signing path (sign-envelope-field.ts) includes protections against this issue, migrating to or enforcing the use of the V2 signing path is recommended. Until an official fix is released, restrict ASSISTANT role permissions or avoid using the vulnerable V1 signing path to prevent exploitation.
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields… (CVE-2026-71247)
Description
Documenso's sign-field-with-token.ts component in the live document-signing UI allows a recipient with the ASSISTANT role to fetch and complete fields of any later-or-equal-order recipient in the same envelope without proper restrictions. This includes the ability to upsert signature records for fields not owned by the acting recipient, enabling an assistant to forge another signer's signature in sequential-signing documents. A newer signing path (sign-envelope-field.ts) mitigates this by blocking assistants from completing signature fields, but this protection is absent in the vulnerable V1 path.
CVSS v3.1
Score 6.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Documenso's sign-field-with-token.ts arises because the handler permits recipients with the ASSISTANT role to fetch and complete fields belonging to any recipient with a later or equal signing order in the same envelope, without verifying that the field type is a signature or that the acting recipient owns the field. This lack of access control allows an assistant to forge signature fields of other signers in sequential signing workflows. The project's newer V2 signing path explicitly prevents assistants from completing signature fields, but this safeguard is missing in the V1 path, making it vulnerable to signature forgery attacks.
Potential Impact
An attacker with the ASSISTANT role can forge signature fields of other recipients in the same envelope, compromising the integrity of the document signing process. This can lead to unauthorized completion of signature fields, potentially invalidating the trustworthiness of signed documents. The vulnerability does not affect confidentiality or availability but impacts the integrity of signatures.
Mitigation Recommendations
No official patch or fix is currently documented for this vulnerability. Since the newer V2 signing path (sign-envelope-field.ts) includes protections against this issue, migrating to or enforcing the use of the V2 signing path is recommended. Until an official fix is released, restrict ASSISTANT role permissions or avoid using the vulnerable V1 signing path to prevent exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v65x-57rf-cpg3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71247"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a735748bf8831d53915a1ba
Added to database: 08/05/2026, 15:31:20 UTC
Last enriched: 08/05/2026, 17:42:54 UTC
Last updated: 09/18/2026, 22:01:37 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.