---
id: CVE-2026-107841
title: >-
  pacioli provides least-privilege governance and a governed agent broker for
  ERPNext
summary: >-
  pacioli provides least-privilege governance and a governed agent broker for
  ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard
  document-layer consent gate allows nested cancellation operations to ride any
  consent establi…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-863
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T19:16:41.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107841'
references:
  - url: >-
      https://github.com/john-broadway/pacioli/commit/f3c7219f5dde6050bd7921e0ac55afd02771250c
    label: security-advisories@github.com
  - url: 'https://github.com/john-broadway/pacioli/releases/tag/guard-v0.10.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/john-broadway/pacioli/security/advisories/GHSA-3hj7-6vmj-h8v4
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107841'
  - url: 'https://github.com/advisories/GHSA-3hj7-6vmj-h8v4'
tags:
  - nvd
  - ghsa
  - pip
ingestedAt: '2026-10-09T19:09:33.757Z'
aliases:
  - GHSA-3hj7-6vmj-h8v4
ecosystem: pip
vendor: pacioli-guard
product: pacioli-guard
affected:
  - 'pacioli-guard >= 0.9.6, < 0.10.0'
patched:
  - pacioli-guard 0.10.0
---

## Overview

pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107841)

Affected packages:

- `pacioli-guard >= 0.9.6, < 0.10.0`

Patched in:

- `pacioli-guard 0.10.0`

Source: https://github.com/advisories/GHSA-3hj7-6vmj-h8v4
