Penpot 是一个开源的设计与原型制作平台。在版本 2.18.0 之前, 函数依赖 Java 的 谓词来判断地址是否被阻止,但该实现未对 NAT64、6to4 或 Teredo 等 IPv6 过渡地址进行分类处理,且仅对 IPv4 地址应用额外的 CIDR 检查。攻击者需要通过 NAT64 网关或利用其控制的 DNS AAAA 记录进行路由,才能实现漏洞利用;而在已部署 NAT64 网关的云端环境中,该漏洞可直接被利用。拥有媒体导入 URL 控制权的用户,或拥有 Webhook URL 控制权的管理员,可以提交嵌
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105691 | 9.9 CRITICAL | Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color |
| CVE-2026-105688 | 6.7 MEDIUM | Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on |
| CVE-2026-105696 | 6.5 MEDIUM | Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link |
| CVE-2026-105695 | 5.9 MEDIUM | Penpot: Missing authorization in chunked-upload assembly lets another authenticated user c |
| CVE-2026-105690 | 5.9 MEDIUM | Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains val |
| CVE-2026-105694 | 5.4 MEDIUM | Penpot: Stored XSS via Unsanitised SVG Uploads |
| CVE-2026-105692 | 5.4 MEDIUM | Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did |
| CVE-2026-105693 | 5.3 MEDIUM | Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle |
| CVE-2026-105686 | 5.3 MEDIUM | Penpot: Repeated chunk index causes temporary-storage amplification |
| CVE-2026-105687 | 4.9 MEDIUM | Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — miss |
| CVE-2026-105684 | 4.3 MEDIUM | Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, |
No comments yet