
CVE-2026-35461 Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows authenticated users to register arbitrary URLs as… https://www.cve.org/CVERecord?id=CVE-2026-35461
Post summary
The post announces that Papra's webhook system (pre‑26.4.0) permits authenticated users to register arbitrary URLs, revealing a potential remote code execution flaw, with no PoC, exploit, patch, or active exploitation details provided.
