Search

Find a vulnerability

Search criteria

    40 vulnerabilities by penpot

    CVE-2026-105696 (GCVE-0-2026-105696)

    Vulnerability from nvd – Published: 2026-10-05 20:05 – Updated: 2026-10-05 20:05
    VLAI
    Title
    Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link's authorized scope via the get-page RPC command
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0.
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link\u0027s authorized pages set. An attacker with both a valid share link and the attacker\u0027s own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:05:30.908Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-x9xg-qphx-8grr",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-x9xg-qphx-8grr"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/52573be07472987703b2ce715c4c10919f4e153e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/52573be07472987703b2ce715c4c10919f4e153e"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-x9xg-qphx-8grr",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link\u0027s authorized scope via the get-page RPC command"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105696",
        "datePublished": "2026-10-05T20:05:30.908Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:05:30.908Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105695 (GCVE-0-2026-105695)

    Vulnerability from nvd – Published: 2026-10-05 20:04 – Updated: 2026-10-05 20:40
    VLAI
    Title
    Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:40 UTC
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105695",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:40:35.188252Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:40:42.567Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user\u0027s live, completed upload-session UUID can assemble the victim\u0027s chunks into the attacker\u0027s own file, team font, or project import, disclosing the uploaded bytes and deleting the victim\u0027s pending session. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:04:22.743Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11012",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11012"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-5vrm-3c6w-gjfv",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim\u0027s upload session"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105695",
        "datePublished": "2026-10-05T20:04:22.743Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:40:42.567Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105694 (GCVE-0-2026-105694)

    Vulnerability from nvd – Published: 2026-10-05 20:02 – Updated: 2026-10-05 20:02
    VLAI
    Title
    Penpot: Stored XSS via Unsanitised SVG Uploads
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim\u0027s Penpot session authority. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:02:03.834Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2"
            },
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/10989",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/10989"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11044",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11044"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-xg6f-5v5x-g4w2",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via Unsanitised SVG Uploads"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105694",
        "datePublished": "2026-10-05T20:02:03.834Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:02:03.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105693 (GCVE-0-2026-105693)

    Vulnerability from nvd – Published: 2026-10-05 19:56 – Updated: 2026-10-05 19:56
    VLAI
    Title
    Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links\u0027 secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:56:47.826Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-w8mf-4x22-24gg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w8mf-4x22-24gg"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/15195b3bbbbf2911b24007ad42453d264a2774d4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/15195b3bbbbf2911b24007ad42453d264a2774d4"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-w8mf-4x22-24gg",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Anonymous share-link token disclosure \u0026 page-scope bypass via get-view-only-bundle"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105693",
        "datePublished": "2026-10-05T19:56:47.826Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:56:47.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105692 (GCVE-0-2026-105692)

    Vulnerability from nvd – Published: 2026-10-05 19:55 – Updated: 2026-10-05 19:55
    VLAI
    Title
    Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.
    CWE
    • CWE-284 - Improper Access Control
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers\u0027 access. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:55:36.410Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-8257-pm4f-cfhq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-8257-pm4f-cfhq"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11290",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11290"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/209aea83658f209c4189b531eeda0f3a638a0294",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/209aea83658f209c4189b531eeda0f3a638a0294"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-8257-pm4f-cfhq",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105692",
        "datePublished": "2026-10-05T19:55:36.410Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:55:36.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105691 (GCVE-0-2026-105691)

    Vulnerability from nvd – Published: 2026-10-05 19:53 – Updated: 2026-10-05 19:53
    VLAI
    Title
    Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object\u0027s fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service\u0027s privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:53:54.552Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11272",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11272"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4f36-m4hj-cv86",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105691",
        "datePublished": "2026-10-05T19:53:54.552Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:53:54.552Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105690 (GCVE-0-2026-105690)

    Vulnerability from nvd – Published: 2026-10-05 19:52 – Updated: 2026-10-05 20:42
    VLAI
    Title
    Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:41 UTC
    CWE
    • CWE-613 - Insufficient Session Expiration
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105690",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:41:59.355159Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:42:46.327Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser\u0027s auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim\u0027s authority until natural expiration. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613: Insufficient Session Expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:52:08.973Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-mj9f-5cwq-7p3q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mj9f-5cwq-7p3q"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/7c85837290c4e7d6f7d99472b092ad4f7c9d6a97",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/7c85837290c4e7d6f7d99472b092ad4f7c9d6a97"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mj9f-5cwq-7p3q",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105690",
        "datePublished": "2026-10-05T19:52:08.973Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T20:42:46.327Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105689 (GCVE-0-2026-105689)

    Vulnerability from nvd – Published: 2026-10-05 19:51 – Updated: 2026-10-05 19:51
    VLAI
    Title
    Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:51:04.208Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-wxgm-8qjw-x445",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-wxgm-8qjw-x445"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/326d83e780ae120b45ccd6f3d7bd24922b54461c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/326d83e780ae120b45ccd6f3d7bd24922b54461c"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-wxgm-8qjw-x445",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105689",
        "datePublished": "2026-10-05T19:51:04.208Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:51:04.208Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105688 (GCVE-0-2026-105688)

    Vulnerability from nvd – Published: 2026-10-05 19:50 – Updated: 2026-10-05 19:50
    VLAI
    Title
    Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:50:01.439Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mx4v-cmxq-644v",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105688",
        "datePublished": "2026-10-05T19:50:01.439Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:50:01.439Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105687 (GCVE-0-2026-105687)

    Vulnerability from nvd – Published: 2026-10-05 19:49 – Updated: 2026-10-05 19:49
    VLAI
    Title
    Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — missing owner-protection
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
    CWE
    • CWE-269 - Improper Privilege Management
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner\u0027s team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:49:04.308Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-j83r-hph3-xpxc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-j83r-hph3-xpxc"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/45f0153e8fb1d9b70f2cb121b15780ba2c2085c4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/45f0153e8fb1d9b70f2cb121b15780ba2c2085c4"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-j83r-hph3-xpxc",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member \u2014 missing owner-protection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105687",
        "datePublished": "2026-10-05T19:49:04.308Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:49:04.308Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105686 (GCVE-0-2026-105686)

    Vulnerability from nvd – Published: 2026-10-05 19:47 – Updated: 2026-10-05 19:47
    VLAI
    Title
    Penpot: Repeated chunk index causes temporary-storage amplification
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session's declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session\u0027s declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770: Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:47:56.283Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/06239844b10b123b7757969ab7618b201d3aba3b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/06239844b10b123b7757969ab7618b201d3aba3b"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-qvq5-c536-pmx8",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Repeated chunk index causes temporary-storage amplification"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105686",
        "datePublished": "2026-10-05T19:47:56.283Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:47:56.283Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105684 (GCVE-0-2026-105684)

    Vulnerability from nvd – Published: 2026-10-05 19:44 – Updated: 2026-10-05 20:32
    VLAI
    Title
    Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scope
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:32 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105684",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:32:21.226027Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:32:28.848Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link\u0027s pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:44:07.526Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-fwm4-hm9f-rmcp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-fwm4-hm9f-rmcp"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/6d9f411fab28a8f60cf807728f4fac2ecb646ca6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/6d9f411fab28a8f60cf807728f4fac2ecb646ca6"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-fwm4-hm9f-rmcp",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Share-link page-scope escape \u2014 comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scope"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105684",
        "datePublished": "2026-10-05T19:44:07.526Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T20:32:28.848Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100868 (GCVE-0-2026-100868)

    Vulnerability from nvd – Published: 2026-09-27 13:09 – Updated: 2026-09-28 15:40
    VLAI
    Title
    Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge
    Summary
    Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:39 UTC
    CWE
    • CWE-1327 - Binding to an Unrestricted IP Address
    Impacted products
    Vendor Product Version
    penpot penpot Affected: 0 , < 2.18.0 (semver)
    Create a notification for this product.
    penpot @penpot/mcp Affected: 0 , ≤ 2.15.4 (semver)
    Create a notification for this product.
    Date Public
    2026-09-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100868",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:39:30.501039Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T15:40:09.957Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "lessThan": "2.18.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "collectionURL": "https://www.npmjs.com",
              "defaultStatus": "unaffected",
              "packageName": "@penpot/mcp",
              "packageURL": "pkg:npm/%40penpot/mcp",
              "product": "@penpot/mcp",
              "vendor": "penpot",
              "versions": [
                {
                  "lessThanOrEqual": "2.15.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:kaleidos:penpot:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.18.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "George Chen"
            }
          ],
          "datePublic": "2026-09-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1327",
                  "description": "Binding to an Unrestricted IP Address",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T13:09:53.387Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-ch2q-6x56-qg5r)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/penpot/penpot/commit/b5274a44766d095247037be18c1d1918ac67ddeb"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/penpot/penpot/blob/1d2c37e52c733f74017d90b0fd1ae2d074a5c33d/mcp/packages/server/src/PluginBridge.ts#L52"
            },
            {
              "name": "GitHub Security Advisory (GHSA-22qr-rp27-j9wm)",
              "tags": [
                "related",
                "vendor-advisory"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/penpot/penpot"
            },
            {
              "name": "VulnCheck Advisory: Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/penpot-before-2.18.0-unauthenticated-websocket-access-via-mcp-bridge"
            }
          ],
          "title": "Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100868",
        "datePublished": "2026-09-27T13:09:53.387Z",
        "dateReserved": "2026-09-27T00:20:54.407Z",
        "dateUpdated": "2026-09-28T15:40:09.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47666 (GCVE-0-2026-47666)

    Vulnerability from nvd – Published: 2026-08-26 22:47 – Updated: 2026-08-27 14:08
    VLAI
    Title
    Penpot: Stored XSS via custom font family name injected into a @font-face style rule
    Summary
    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style through innerHTML, a name containing markup such as a closing style tag followed by a script can break out of the style element and execute JavaScript on the Penpot origin. The attack is passive: any team member who opens a file referencing the malicious font triggers script execution simply by rendering the page, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 14:08 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.15.3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47666",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T14:08:34.260001Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T14:08:58.826Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.15.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style through innerHTML, a name containing markup such as a closing style tag followed by a script can break out of the style element and execute JavaScript on the Penpot origin. The attack is passive: any team member who opens a file referencing the malicious font triggers script execution simply by rendering the page, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T22:47:49.788Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/67d95679711da538b3b22a873bcb6c197104dc0c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/67d95679711da538b3b22a873bcb6c197104dc0c"
            }
          ],
          "source": {
            "advisory": "GHSA-w5hh-gj5c-5wpc",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via custom font family name injected into a @font-face style rule"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-47666",
        "datePublished": "2026-08-26T22:47:49.788Z",
        "dateReserved": "2026-05-19T21:10:38.797Z",
        "dateUpdated": "2026-08-27T14:08:58.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47665 (GCVE-0-2026-47665)

    Vulnerability from nvd – Published: 2026-08-26 22:50 – Updated: 2026-08-27 15:16
    VLAI
    Title
    Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML
    Summary
    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error handler or script that executes in the browser of every other collaborator. The attack is passive: any user who opens the comments panel on the affected file triggers script execution on the Penpot origin, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 15:16 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.15.3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47665",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T15:16:13.340045Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T15:16:47.257Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.15.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error handler or script that executes in the browser of every other collaborator. The attack is passive: any user who opens the comments panel on the affected file triggers script execution on the Penpot origin, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T22:50:34.362Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/29f940fb7ab521033b1e276b8285afbc3609df6c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/29f940fb7ab521033b1e276b8285afbc3609df6c"
            }
          ],
          "source": {
            "advisory": "GHSA-vc72-6r45-q988",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-47665",
        "datePublished": "2026-08-26T22:50:34.362Z",
        "dateReserved": "2026-05-19T21:10:38.797Z",
        "dateUpdated": "2026-08-27T15:16:47.257Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105696 (GCVE-0-2026-105696)

    Vulnerability from cvelistv5 – Published: 2026-10-05 20:05 – Updated: 2026-10-05 20:05
    VLAI
    Title
    Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link's authorized scope via the get-page RPC command
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0.
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link\u0027s authorized pages set. An attacker with both a valid share link and the attacker\u0027s own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:05:30.908Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-x9xg-qphx-8grr",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-x9xg-qphx-8grr"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/52573be07472987703b2ce715c4c10919f4e153e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/52573be07472987703b2ce715c4c10919f4e153e"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-x9xg-qphx-8grr",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link\u0027s authorized scope via the get-page RPC command"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105696",
        "datePublished": "2026-10-05T20:05:30.908Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:05:30.908Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105695 (GCVE-0-2026-105695)

    Vulnerability from cvelistv5 – Published: 2026-10-05 20:04 – Updated: 2026-10-05 20:40
    VLAI
    Title
    Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:40 UTC
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105695",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:40:35.188252Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:40:42.567Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user\u0027s live, completed upload-session UUID can assemble the victim\u0027s chunks into the attacker\u0027s own file, team font, or project import, disclosing the uploaded bytes and deleting the victim\u0027s pending session. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:04:22.743Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11012",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11012"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-5vrm-3c6w-gjfv",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim\u0027s upload session"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105695",
        "datePublished": "2026-10-05T20:04:22.743Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:40:42.567Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105694 (GCVE-0-2026-105694)

    Vulnerability from cvelistv5 – Published: 2026-10-05 20:02 – Updated: 2026-10-05 20:02
    VLAI
    Title
    Penpot: Stored XSS via Unsanitised SVG Uploads
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim\u0027s Penpot session authority. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T20:02:03.834Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2"
            },
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/10989",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/10989"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11044",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11044"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-xg6f-5v5x-g4w2",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via Unsanitised SVG Uploads"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105694",
        "datePublished": "2026-10-05T20:02:03.834Z",
        "dateReserved": "2026-10-05T17:48:58.627Z",
        "dateUpdated": "2026-10-05T20:02:03.834Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105693 (GCVE-0-2026-105693)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:56 – Updated: 2026-10-05 19:56
    VLAI
    Title
    Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
    CWE
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links\u0027 secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:56:47.826Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-w8mf-4x22-24gg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w8mf-4x22-24gg"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/15195b3bbbbf2911b24007ad42453d264a2774d4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/15195b3bbbbf2911b24007ad42453d264a2774d4"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-w8mf-4x22-24gg",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Anonymous share-link token disclosure \u0026 page-scope bypass via get-view-only-bundle"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105693",
        "datePublished": "2026-10-05T19:56:47.826Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:56:47.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105692 (GCVE-0-2026-105692)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:55 – Updated: 2026-10-05 19:55
    VLAI
    Title
    Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.
    CWE
    • CWE-284 - Improper Access Control
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers\u0027 access. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:55:36.410Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-8257-pm4f-cfhq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-8257-pm4f-cfhq"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11290",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11290"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/209aea83658f209c4189b531eeda0f3a638a0294",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/209aea83658f209c4189b531eeda0f3a638a0294"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-8257-pm4f-cfhq",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105692",
        "datePublished": "2026-10-05T19:55:36.410Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:55:36.410Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105691 (GCVE-0-2026-105691)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:53 – Updated: 2026-10-05 19:53
    VLAI
    Title
    Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object\u0027s fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service\u0027s privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:53:54.552Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86"
            },
            {
              "name": "https://github.com/penpot/penpot/pull/11272",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/pull/11272"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4f36-m4hj-cv86",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105691",
        "datePublished": "2026-10-05T19:53:54.552Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:53:54.552Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105690 (GCVE-0-2026-105690)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:52 – Updated: 2026-10-05 20:42
    VLAI
    Title
    Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:41 UTC
    CWE
    • CWE-613 - Insufficient Session Expiration
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105690",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:41:59.355159Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:42:46.327Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser\u0027s auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim\u0027s authority until natural expiration. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-613",
                  "description": "CWE-613: Insufficient Session Expiration",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:52:08.973Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-mj9f-5cwq-7p3q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mj9f-5cwq-7p3q"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/7c85837290c4e7d6f7d99472b092ad4f7c9d6a97",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/7c85837290c4e7d6f7d99472b092ad4f7c9d6a97"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mj9f-5cwq-7p3q",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105690",
        "datePublished": "2026-10-05T19:52:08.973Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T20:42:46.327Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105689 (GCVE-0-2026-105689)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:51 – Updated: 2026-10-05 19:51
    VLAI
    Title
    Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:51:04.208Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-wxgm-8qjw-x445",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-wxgm-8qjw-x445"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/326d83e780ae120b45ccd6f3d7bd24922b54461c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/326d83e780ae120b45ccd6f3d7bd24922b54461c"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-wxgm-8qjw-x445",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105689",
        "datePublished": "2026-10-05T19:51:04.208Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:51:04.208Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105688 (GCVE-0-2026-105688)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:50 – Updated: 2026-10-05 19:50
    VLAI
    Title
    Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:50:01.439Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mx4v-cmxq-644v",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105688",
        "datePublished": "2026-10-05T19:50:01.439Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:50:01.439Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105687 (GCVE-0-2026-105687)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:49 – Updated: 2026-10-05 19:49
    VLAI
    Title
    Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — missing owner-protection
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
    CWE
    • CWE-269 - Improper Privilege Management
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner\u0027s team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 4.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:49:04.308Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-j83r-hph3-xpxc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-j83r-hph3-xpxc"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/45f0153e8fb1d9b70f2cb121b15780ba2c2085c4",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/45f0153e8fb1d9b70f2cb121b15780ba2c2085c4"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-j83r-hph3-xpxc",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member \u2014 missing owner-protection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105687",
        "datePublished": "2026-10-05T19:49:04.308Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:49:04.308Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105686 (GCVE-0-2026-105686)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:47 – Updated: 2026-10-05 19:47
    VLAI
    Title
    Penpot: Repeated chunk index causes temporary-storage amplification
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session's declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0.
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session\u0027s declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770: Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:47:56.283Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-qvq5-c536-pmx8"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/06239844b10b123b7757969ab7618b201d3aba3b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/06239844b10b123b7757969ab7618b201d3aba3b"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-qvq5-c536-pmx8",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Repeated chunk index causes temporary-storage amplification"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105686",
        "datePublished": "2026-10-05T19:47:56.283Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T19:47:56.283Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105684 (GCVE-0-2026-105684)

    Vulnerability from cvelistv5 – Published: 2026-10-05 19:44 – Updated: 2026-10-05 20:32
    VLAI
    Title
    Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scope
    Summary
    Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 20:32 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.18.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105684",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T20:32:21.226027Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T20:32:28.848Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.18.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link\u0027s pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T19:44:07.526Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-fwm4-hm9f-rmcp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-fwm4-hm9f-rmcp"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/6d9f411fab28a8f60cf807728f4fac2ecb646ca6",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/6d9f411fab28a8f60cf807728f4fac2ecb646ca6"
            },
            {
              "name": "https://github.com/penpot/penpot/releases/tag/2.18.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/releases/tag/2.18.0"
            }
          ],
          "source": {
            "advisory": "GHSA-fwm4-hm9f-rmcp",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Share-link page-scope escape \u2014 comment RPCs leak comment content, author identity, and all page-ids for pages outside the share scope"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105684",
        "datePublished": "2026-10-05T19:44:07.526Z",
        "dateReserved": "2026-10-05T17:48:58.626Z",
        "dateUpdated": "2026-10-05T20:32:28.848Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-100868 (GCVE-0-2026-100868)

    Vulnerability from cvelistv5 – Published: 2026-09-27 13:09 – Updated: 2026-09-28 15:40
    VLAI
    Title
    Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge
    Summary
    Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 15:39 UTC
    CWE
    • CWE-1327 - Binding to an Unrestricted IP Address
    Impacted products
    Vendor Product Version
    penpot penpot Affected: 0 , < 2.18.0 (semver)
    Create a notification for this product.
    penpot @penpot/mcp Affected: 0 , ≤ 2.15.4 (semver)
    Create a notification for this product.
    Date Public
    2026-09-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-100868",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T15:39:30.501039Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T15:40:09.957Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "lessThan": "2.18.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "collectionURL": "https://www.npmjs.com",
              "defaultStatus": "unaffected",
              "packageName": "@penpot/mcp",
              "packageURL": "pkg:npm/%40penpot/mcp",
              "product": "@penpot/mcp",
              "vendor": "penpot",
              "versions": [
                {
                  "lessThanOrEqual": "2.15.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:kaleidos:penpot:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "2.18.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "George Chen"
            }
          ],
          "datePublic": "2026-09-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1327",
                  "description": "Binding to an Unrestricted IP Address",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-27T13:09:53.387Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-ch2q-6x56-qg5r)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/penpot/penpot/commit/b5274a44766d095247037be18c1d1918ac67ddeb"
            },
            {
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/penpot/penpot/blob/1d2c37e52c733f74017d90b0fd1ae2d074a5c33d/mcp/packages/server/src/PluginBridge.ts#L52"
            },
            {
              "name": "GitHub Security Advisory (GHSA-22qr-rp27-j9wm)",
              "tags": [
                "related",
                "vendor-advisory"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/penpot/penpot"
            },
            {
              "name": "VulnCheck Advisory: Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/penpot-before-2.18.0-unauthenticated-websocket-access-via-mcp-bridge"
            }
          ],
          "title": "Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-100868",
        "datePublished": "2026-09-27T13:09:53.387Z",
        "dateReserved": "2026-09-27T00:20:54.407Z",
        "dateUpdated": "2026-09-28T15:40:09.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47665 (GCVE-0-2026-47665)

    Vulnerability from cvelistv5 – Published: 2026-08-26 22:50 – Updated: 2026-08-27 15:16
    VLAI
    Title
    Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML
    Summary
    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error handler or script that executes in the browser of every other collaborator. The attack is passive: any user who opens the comments panel on the affected file triggers script execution on the Penpot origin, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 15:16 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.15.3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47665",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T15:16:13.340045Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T15:16:47.257Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.15.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error handler or script that executes in the browser of every other collaborator. The attack is passive: any user who opens the comments panel on the affected file triggers script execution on the Penpot origin, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T22:50:34.362Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-vc72-6r45-q988"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/29f940fb7ab521033b1e276b8285afbc3609df6c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/29f940fb7ab521033b1e276b8285afbc3609df6c"
            }
          ],
          "source": {
            "advisory": "GHSA-vc72-6r45-q988",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-47665",
        "datePublished": "2026-08-26T22:50:34.362Z",
        "dateReserved": "2026-05-19T21:10:38.797Z",
        "dateUpdated": "2026-08-27T15:16:47.257Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47666 (GCVE-0-2026-47666)

    Vulnerability from cvelistv5 – Published: 2026-08-26 22:47 – Updated: 2026-08-27 14:08
    VLAI
    Title
    Penpot: Stored XSS via custom font family name injected into a @font-face style rule
    Summary
    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style through innerHTML, a name containing markup such as a closing style tag followed by a script can break out of the style element and execute JavaScript on the Penpot origin. The attack is passive: any team member who opens a file referencing the malicious font triggers script execution simply by rendering the page, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-27 14:08 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    penpot penpot Affected: < 2.15.3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47666",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-27T14:08:34.260001Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-27T14:08:58.826Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "penpot",
              "vendor": "penpot",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 2.15.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style through innerHTML, a name containing markup such as a closing style tag followed by a script can break out of the style element and execute JavaScript on the Penpot origin. The attack is passive: any team member who opens a file referencing the malicious font triggers script execution simply by rendering the page, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-26T22:47:49.788Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/penpot/penpot/security/advisories/GHSA-w5hh-gj5c-5wpc"
            },
            {
              "name": "https://github.com/penpot/penpot/commit/67d95679711da538b3b22a873bcb6c197104dc0c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/penpot/penpot/commit/67d95679711da538b3b22a873bcb6c197104dc0c"
            }
          ],
          "source": {
            "advisory": "GHSA-w5hh-gj5c-5wpc",
            "discovery": "UNKNOWN"
          },
          "title": "Penpot: Stored XSS via custom font family name injected into a @font-face style rule"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-47666",
        "datePublished": "2026-08-26T22:47:49.788Z",
        "dateReserved": "2026-05-19T21:10:38.797Z",
        "dateUpdated": "2026-08-27T14:08:58.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }