Documenso · Documenso · CVE-2026-13543
**Name of the Vulnerable Software and Affected Versions**
Documenso versions prior to 2.11.1
**Description**
Improper authentication exists in the Google OAuth Login component within the file `packages/auth/server/lib/utils/handle-oauth-callback-url.ts`. This issue allows a remote attacker to manipulate the authentication process, although the attack is characterized by high complexity and is difficult to exploit.
**Recommendations**
Update to a version newer than 2.11.0.
Restrict the use of the Google OAuth Login functionality until the pending fix is officially released and applied.