Penpot 是一个开源的设计与原型制作平台。在版本 2.18.0 之前,SVG 导出功能会将攻击者可控的文本对象的颜色填充值插入到 ppmcolormask 命令字符串中,并通过 child_process.exec 执行该字符串。能够编辑文件的用户可以在填充颜色中嵌入 Shell 元字符,并触发 SVG 导出,从而以导出服务的权限执行任意命令。此外,通过指向恶意文件的有效公开分享链接,也可触发相同的导出操作。此漏洞已在版本 2.18.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105688 | 6.7 MEDIUM | Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on |
| CVE-2026-105696 | 6.5 MEDIUM | Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link |
| CVE-2026-105689 | 6.0 MEDIUM | Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook del |
| CVE-2026-105695 | 5.9 MEDIUM | Penpot: Missing authorization in chunked-upload assembly lets another authenticated user c |
| CVE-2026-105690 | 5.9 MEDIUM | Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains val |
| CVE-2026-105694 | 5.4 MEDIUM | Penpot: Stored XSS via Unsanitised SVG Uploads |
| CVE-2026-105692 | 5.4 MEDIUM | Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did |
| CVE-2026-105693 | 5.3 MEDIUM | Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle |
| CVE-2026-105686 | 5.3 MEDIUM | Penpot: Repeated chunk index causes temporary-storage amplification |
| CVE-2026-105687 | 4.9 MEDIUM | Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — miss |
| CVE-2026-105684 | 4.3 MEDIUM | Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, |
No comments yet