penpot
15 known vulnerabilities in penpot, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105696 CVSS 6.5 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with…
- CVE-2026-105695 CVSS 5.9 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its…
- CVE-2026-105694 CVSS 5.4 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG…
- CVE-2026-105693 CVSS 5.3 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every…
- CVE-2026-105692 CVSS 5.4 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected…
- CVE-2026-105691 CVSS 9.9 critical Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's…
- CVE-2026-105690 CVSS 5.9 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking…
- CVE-2026-105689 CVSS 6.0 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress…
- CVE-2026-105688 CVSS 6.7 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path…
- CVE-2026-105687 CVSS 4.9 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to…
- CVE-2026-105686 CVSS 5.3 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in…
- CVE-2026-105684 CVSS 4.3 medium Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments…
- CVE-2026-100868 CVSS 5.3 medium Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode…
- CVE-2026-47666 CVSS 7.6 high Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored…
- CVE-2026-47665 CVSS 8.7 high Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored…