Documenso versions before 2.13.0 contain a critical vulnerability in the /api/files/upload-pdf endpoint that allows unauthenticated file uploads. The endpoint does not require authentication, session tokens, or API credentials, enabling any unauthenticated attacker to upload arbitrary PDF files. This flaw can be exploited to exhaust storage resources or flood the database with unlinked document records, constituting a Denial of Service (DoS) risk. The vulnerability was patched in version 2.13.0. A commit fixing the issue is available on the Documenso GitHub repository. The issue was also documented by VulnCheck in a dedicated advisory.