Skip to main content
EPSS 0.2%top 93%

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields… (CVE-2026-71247)

0
Medium
Published: 08/05/2026 (08/05/2026, 12:31:32 UTC)
Source: GCVE Database

Description

Documenso's sign-field-with-token.ts component in the live document-signing UI allows a recipient with the ASSISTANT role to fetch and complete fields of any later-or-equal-order recipient in the same envelope without proper restrictions. This includes the ability to upsert signature records for fields not owned by the acting recipient, enabling an assistant to forge another signer's signature in sequential-signing documents. A newer signing path (sign-envelope-field.ts) mitigates this by blocking assistants from completing signature fields, but this protection is absent in the vulnerable V1 path.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:42:54 UTC

Technical Analysis

The vulnerability in Documenso's sign-field-with-token.ts arises because the handler permits recipients with the ASSISTANT role to fetch and complete fields belonging to any recipient with a later or equal signing order in the same envelope, without verifying that the field type is a signature or that the acting recipient owns the field. This lack of access control allows an assistant to forge signature fields of other signers in sequential signing workflows. The project's newer V2 signing path explicitly prevents assistants from completing signature fields, but this safeguard is missing in the V1 path, making it vulnerable to signature forgery attacks.

Potential Impact

An attacker with the ASSISTANT role can forge signature fields of other recipients in the same envelope, compromising the integrity of the document signing process. This can lead to unauthorized completion of signature fields, potentially invalidating the trustworthiness of signed documents. The vulnerability does not affect confidentiality or availability but impacts the integrity of signatures.

Mitigation Recommendations

No official patch or fix is currently documented for this vulnerability. Since the newer V2 signing path (sign-envelope-field.ts) includes protections against this issue, migrating to or enforcing the use of the V2 signing path is recommended. Until an official fix is released, restrict ASSISTANT role permissions or avoid using the vulnerable V1 signing path to prevent exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-v65x-57rf-cpg3
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71247"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a735748bf8831d53915a1ba

Added to database: 08/05/2026, 15:31:20 UTC

Last enriched: 08/05/2026, 17:42:54 UTC

Last updated: 09/18/2026, 22:01:37 UTC

Views: 64

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses