[GH-ISSUE #1837] API appears to allow sending any document not owned by you #530

Closed
opened 2026-02-26 18:47:27 +03:00 by kerem · 4 comments
Owner

Originally created by @cityofaikensc on GitHub (Jun 12, 2025).
Original GitHub issue: https://github.com/documenso/documenso/issues/1837

Issue Description

It appears that using the API, I am able to send documents for signing without owning them from any account. The response contains information that could be used for malicious purposes.

Steps to Reproduce

POST URL: https://app.documenso.com/api/v1/documents/Random ID/send
Authorization Key: Your own generated authorization key
sendEmail: true

Expected Behavior

Unknown document ID

Screenshots (optional)

No response

Operating System [e.g., Windows 10]

No response

Browser [e.g., Chrome, Firefox]

No response

Version [e.g., 2.0.1]

No response

Please check the boxes that apply to this issue report.

  • I have searched the existing issues to make sure this is not a duplicate.
  • I have provided steps to reproduce the issue.
  • I have included relevant environment information.
  • I have included any relevant screenshots.
  • I understand that this is a voluntary contribution and that there is no guarantee of resolution.
  • I want to work on creating a PR for this issue if approved
Originally created by @cityofaikensc on GitHub (Jun 12, 2025). Original GitHub issue: https://github.com/documenso/documenso/issues/1837 ### Issue Description It appears that using the API, I am able to send documents for signing without owning them from any account. The response contains information that could be used for malicious purposes. ### Steps to Reproduce POST URL: https://app.documenso.com/api/v1/documents/Random ID/send Authorization Key: Your own generated authorization key sendEmail: true ### Expected Behavior Unknown document ID ### Screenshots (optional) _No response_ ### Operating System [e.g., Windows 10] _No response_ ### Browser [e.g., Chrome, Firefox] _No response_ ### Version [e.g., 2.0.1] _No response_ ### Please check the boxes that apply to this issue report. - [x] I have searched the existing issues to make sure this is not a duplicate. - [x] I have provided steps to reproduce the issue. - [ ] I have included relevant environment information. - [ ] I have included any relevant screenshots. - [x] I understand that this is a voluntary contribution and that there is no guarantee of resolution. - [ ] I want to work on creating a PR for this issue if approved
kerem 2026-02-26 18:47:27 +03:00
Author
Owner

@github-actions[bot] commented on GitHub (Jun 12, 2025):

Thank you for opening your first issue and for being a part of the open signing revolution!

One of our team members will review it and get back to you as soon as it possible 💚

Meanwhile, please feel free to hop into our community in Discord

<!-- gh-comment-id:2966684250 --> @github-actions[bot] commented on GitHub (Jun 12, 2025): Thank you for opening your first issue and for being a part of the open signing revolution! <br /> One of our team members will review it and get back to you as soon as it possible 💚 <br /> Meanwhile, please feel free to hop into our community in [Discord](https://documen.so/discord)
Author
Owner

@dguyen commented on GitHub (Jun 12, 2025):

Thanks, we'll look into this now and will reopen soon

<!-- gh-comment-id:2966858480 --> @dguyen commented on GitHub (Jun 12, 2025): Thanks, we'll look into this now and will reopen soon
Author
Owner

@dguyen commented on GitHub (Jun 12, 2025):

Hey! Thanks for finding the issue and reporting it to us, we appreciate it a lot.

We've now fixed the issue and are currently looking into it in more detail to see why it happened in the first place

<!-- gh-comment-id:2967464040 --> @dguyen commented on GitHub (Jun 12, 2025): Hey! Thanks for finding the issue and reporting it to us, we appreciate it a lot. We've now fixed the issue and are currently looking into it in more detail to see why it happened in the first place
Author
Owner

@cityofaikensc commented on GitHub (Jun 12, 2025):

David,

Thank you so much for the update and appreciate the quick turnaround on this issue.

Take care

Wesley Funderberg

Assistant Director - Information Technology Department

City of Aiken, SC Government

Municipal Building

111 Chesterfield St. S

Aiken, SC 29801

Office: 803-293-7885

Email: @.***

Web: https://www.cityofaikensc.govhttps://www.cityofaikensc.gov/

Email correspondence to and from this address is subject to the South Carolina Public Records Law and may be disclosed to third parties by an authorized City official. Unauthorized disclosure of juvenile, health, legally privileged, or otherwise confidential information, including confidential information relating to an ongoing City procurement effort, is prohibited. If you have received this email in error, please notify the sender immediately and delete all records of this email.

From: David Nguyen @.>
Date: Thursday, June 12, 2025 at 12:19 PM
To: documenso/documenso @.
>
Cc: Wesley Funderberg @.>, Author @.>
Subject: [Newsletter] [EXTERNAL] - Re: [documenso/documenso] API appears to allow sending any document not owned by you (Issue #1837)

You don't often get email from @.*** Learn why this is importanthttps://aka.ms/LearnAboutSenderIdentification

CAUTION: This email originated outside the City of Aiken. DO NOT click links or open attachments unless you recognize the sender and know the content is safe.

[https://avatars.githubusercontent.com/u/20962767?s=20&v=4]dguyen left a comment (documenso/documenso#1837)https://github.com/documenso/documenso/issues/1837#issuecomment-2967464040

Hey! Thanks for finding the issue and reporting it to us, we appreciate it a lot.

We've now fixed the issue and are currently looking into it in more detail


Reply to this email directly, view it on GitHubhttps://github.com/documenso/documenso/issues/1837#issuecomment-2967464040, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AEZOCKK2C2S6BAYUVPZR5FT3DGSA5AVCNFSM6AAAAAB7FNEBI6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDSNRXGQ3DIMBUGA.
You are receiving this because you authored the thread.

Email correspondence to and from this address is subject to the South Carolina Public Records Law and may be disclosed to third parties by an authorized City official. Unauthorized disclosure to juvenile, health, legally privileged, or otherwise confidential information, including confidential information relating to an ongoing City procurement effort, is prohibited by law. If you have received this email in error, please notify the sender immediately and delete all records of this email.

<!-- gh-comment-id:2967724473 --> @cityofaikensc commented on GitHub (Jun 12, 2025): David, Thank you so much for the update and appreciate the quick turnaround on this issue. Take care Wesley Funderberg Assistant Director - Information Technology Department City of Aiken, SC Government Municipal Building 111 Chesterfield St. S Aiken, SC 29801 Office: 803-293-7885 Email: ***@***.*** Web: https://www.cityofaikensc.gov<https://www.cityofaikensc.gov/> Email correspondence to and from this address is subject to the South Carolina Public Records Law and may be disclosed to third parties by an authorized City official. Unauthorized disclosure of juvenile, health, legally privileged, or otherwise confidential information, including confidential information relating to an ongoing City procurement effort, is prohibited. If you have received this email in error, please notify the sender immediately and delete all records of this email. From: David Nguyen ***@***.***> Date: Thursday, June 12, 2025 at 12:19 PM To: documenso/documenso ***@***.***> Cc: Wesley Funderberg ***@***.***>, Author ***@***.***> Subject: [*Newsletter*] [EXTERNAL] - Re: [documenso/documenso] API appears to allow sending any document not owned by you (Issue #1837) You don't often get email from ***@***.*** Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> CAUTION: This email originated outside the City of Aiken. DO NOT click links or open attachments unless you recognize the sender and know the content is safe. [https://avatars.githubusercontent.com/u/20962767?s=20&v=4]dguyen left a comment (documenso/documenso#1837)<https://github.com/documenso/documenso/issues/1837#issuecomment-2967464040> Hey! Thanks for finding the issue and reporting it to us, we appreciate it a lot. We've now fixed the issue and are currently looking into it in more detail — Reply to this email directly, view it on GitHub<https://github.com/documenso/documenso/issues/1837#issuecomment-2967464040>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AEZOCKK2C2S6BAYUVPZR5FT3DGSA5AVCNFSM6AAAAAB7FNEBI6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDSNRXGQ3DIMBUGA>. You are receiving this because you authored the thread. Email correspondence to and from this address is subject to the South Carolina Public Records Law and may be disclosed to third parties by an authorized City official. Unauthorized disclosure to juvenile, health, legally privileged, or otherwise confidential information, including confidential information relating to an ongoing City procurement effort, is prohibited by law. If you have received this email in error, please notify the sender immediately and delete all records of this email.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/documenso#530
No description provided.