{"id":"PYSEC-2026-1309","summary":"Docassemble unauthorized access through URL manipulation","details":"### Impact\nThe vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96.\n\n### Patches\nThe vulnerability has been patched in version 1.4.97 of the master branch. The Docker image on docker.io has been patched.\n\n### Workarounds\nIf upgrading is not possible, manually apply the changes of [97f77dc](https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9) and restart the server.\n\n### Credit\n\nThe vulnerability was discovered by Riyush Ghimire (@richighimi).\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [docassemble](https://github.com/jhpyle/docassemble/issues)\n* Join the [Slack channel](https://join.slack.com/t/docassemble/shared_invite/zt-2cspzjo9j-YyE7SrLmi5muAvnPv~Bz~A)\n* Email us at jhpyle@gmail.com","aliases":["CVE-2024-27292","GHSA-jq57-3w7p-vwvv","PYSEC-2026-2453"],"modified":"2026-07-13T16:43:08.946030010Z","published":"2026-07-07T11:45:33.791686Z","references":[{"type":"WEB","url":"https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27292"},{"type":"WEB","url":"https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9"},{"type":"PACKAGE","url":"https://github.com/jhpyle/docassemble"},{"type":"PACKAGE","url":"https://pypi.org/project/docassemble-base"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jq57-3w7p-vwvv"}],"affected":[{"package":{"name":"docassemble-base","ecosystem":"PyPI","purl":"pkg:pypi/docassemble-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.4.53"},{"fixed":"1.4.97"}]}],"versions":["1.4.53","1.4.54","1.4.55","1.4.56","1.4.57","1.4.58","1.4.59","1.4.60","1.4.61","1.4.62","1.4.63","1.4.64","1.4.65","1.4.66","1.4.67","1.4.68","1.4.69","1.4.70","1.4.71","1.4.72","1.4.73","1.4.74","1.4.75","1.4.76","1.4.77","1.4.78","1.4.79","1.4.80","1.4.81","1.4.82","1.4.83","1.4.84","1.4.85","1.4.86","1.4.87","1.4.88","1.4.89","1.4.90","1.4.91","1.4.92","1.4.93","1.4.94","1.4.95","1.4.96"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/docassemble-base/PYSEC-2026-1309.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}