{"id":"GHSA-qrmm-w4v4-q7f8","title":"Unauthorized access through URL manipulation","summary":"Unauthorized access through URL manipulation","severity":"high","vendor":"docassemble","product":"docassemble","ecosystem":"pip","affected":["docassemble < 1.2.65"],"patched":["docassemble 1.2.65"],"published":"2021-05-06","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:14.990661136Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qrmm-w4v4-q7f8","references":[{"url":"https://github.com/jhpyle/docassemble/security/advisories/GHSA-qrmm-w4v4-q7f8"}],"tags":["osv","pip"],"ingestedAt":"2026-09-12T03:13:01.723Z","slug":"GHSA-qrmm-w4v4-q7f8","body":"## Overview\n\n### Impact\nThe vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation.\n\n### Patches\nThe vulnerability has been patched in version 1.2.65 of the `master` branch, version 1.1.113 of the 1.1.x series, and version 1.0.12 of the `stable` branch. The Docker image on docker.io has been patched.\n\n### Workarounds\nIf upgrading is not possible, manually apply the changes of https://github.com/jhpyle/docassemble/commit/e3dbf6ce054b3c0310996f0657289f5eed0a73fe and restart the server (e.g., by pressing Save on the Configuration screen).\n\n### Credit\nThe vulnerability was discovered by Jim Platania of Seiso LLC (@jimmio).\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [docassemble](https://github.com/jhpyle/docassemble/issues)\n* Join the [Slack channel](https://join.slack.com/t/docassemble/shared_invite/zt-ohrn8y9z-_Fb3RAl~JPBU6Km7odBPfQ)\n* Email us at [jhpyle@gmail.com](mailto:jhpyle@gmail.com)\n\n\n## Affected packages\n\n- `docassemble < 1.2.65`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `docassemble 1.2.65`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}