id: PYSEC-2026-2453 published: "2026-07-13T14:20:03.261384Z" modified: "2026-07-13T16:03:55.442215Z" aliases: - CVE-2024-27292 - GHSA-jq57-3w7p-vwvv summary: Docassemble unauthorized access through URL manipulation details: "### Impact\nThe vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96.\n\n### Patches\nThe vulnerability has been patched in version 1.4.97 of the master branch. The Docker image on docker.io has been patched.\n\n### Workarounds\nIf upgrading is not possible, manually apply the changes of [97f77dc](https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9) and restart the server.\n\n### Credit\n\nThe vulnerability was discovered by Riyush Ghimire (@richighimi).\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [docassemble](https://github.com/jhpyle/docassemble/issues)\n* Join the [Slack channel](https://join.slack.com/t/docassemble/shared_invite/zt-2cspzjo9j-YyE7SrLmi5muAvnPv~Bz~A)\n* Email us at jhpyle@gmail.com" affected: - package: name: docassemble-webapp ecosystem: PyPI purl: pkg:pypi/docassemble-webapp ranges: - type: ECOSYSTEM events: - introduced: 1.4.53 - fixed: 1.4.97 versions: - 1.4.53 - 1.4.54 - 1.4.55 - 1.4.56 - 1.4.57 - 1.4.58 - 1.4.59 - 1.4.60 - 1.4.61 - 1.4.62 - 1.4.63 - 1.4.64 - 1.4.65 - 1.4.66 - 1.4.67 - 1.4.68 - 1.4.69 - 1.4.70 - 1.4.71 - 1.4.72 - 1.4.73 - 1.4.74 - 1.4.75 - 1.4.76 - 1.4.77 - 1.4.78 - 1.4.79 - 1.4.80 - 1.4.81 - 1.4.82 - 1.4.83 - 1.4.84 - 1.4.85 - 1.4.86 - 1.4.87 - 1.4.88 - 1.4.89 - 1.4.90 - 1.4.91 - 1.4.92 - 1.4.93 - 1.4.94 - 1.4.95 - 1.4.96 references: - type: WEB url: https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvv - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-27292 - type: WEB url: https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabd600c9 - type: PACKAGE url: https://github.com/jhpyle/docassemble - type: PACKAGE url: https://pypi.org/project/docassemble-webapp - type: ADVISORY url: https://github.com/advisories/GHSA-jq57-3w7p-vwvv severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N