Opensignlabs · Opensign · CVE-2026-72544
**Name of the Vulnerable Software and Affected Versions**
OpenSignLabs OpenSign versions prior to 2.37.1
**Description**
An integrity verification issue allows unauthenticated remote attackers to forge document audit-trail entries. This is possible through the `triggerevent Parse` cloud function, which accepts viewer identity and IP address as caller-supplied parameters without authentication. By exploiting this, an attacker can fabricate arbitrary audit log entries and tamper with the legal audit trail of any signed document, undermining non-repudiation, which is the assurance that someone cannot deny the validity of something.
**Recommendations**
Update OpenSignLabs OpenSign to version 2.37.1 or later.
As a temporary workaround, restrict access to the `triggerevent Parse` cloud function to minimize the risk of exploitation.