Penpot 在 2.18.0 版本之前,在单用户模式下会将 MCP 服务器插件的 WebSocket 桥接绑定到所有网络接口,且未进行身份验证。处于相邻网络的未授权攻击者可以连接到 WebSocket 端口,伪装成 Penpot 浏览器插件,拦截任务载荷,并向 MCP 客户端返回伪造的结果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| penpot | @penpot/mcp | ≤ 2.15.4 |
affected |
| penpot | penpot | < 2.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| penpot | penpot | 0 ~ 2.18.0 | - |
|
| penpot | @penpot/mcp | 0 ~ 2.15.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet