Penpot 是一个开源的设计与原型制作平台。在版本 2.18.0 之前, RPC 接口允许使用带有广泛读取权限的分享链接访问对象,但未验证调用者指定的页面 ID 是否属于该链接所授权的页面集合。因此,如果攻击者同时拥有一个有效的分享链接和自己的已认证 Penpot 会话,并且知道目标页面的标识符,即可通过需认证的 接口获取同一文件中其他页面的完整形状和设计数据。此外,相关的 RPC 接口也允许通过分享链接访问文件片段,但未将片段映射到受授权的页面。该问题已在版本 2.18.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105691 | 9.9 CRITICAL | Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color |
| CVE-2026-105688 | 6.7 MEDIUM | Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on |
| CVE-2026-105689 | 6.0 MEDIUM | Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook del |
| CVE-2026-105695 | 5.9 MEDIUM | Penpot: Missing authorization in chunked-upload assembly lets another authenticated user c |
| CVE-2026-105690 | 5.9 MEDIUM | Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains val |
| CVE-2026-105694 | 5.4 MEDIUM | Penpot: Stored XSS via Unsanitised SVG Uploads |
| CVE-2026-105692 | 5.4 MEDIUM | Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did |
| CVE-2026-105693 | 5.3 MEDIUM | Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle |
| CVE-2026-105686 | 5.3 MEDIUM | Penpot: Repeated chunk index causes temporary-storage amplification |
| CVE-2026-105687 | 4.9 MEDIUM | Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — miss |
| CVE-2026-105684 | 4.3 MEDIUM | Penpot: Share-link page-scope escape — comment RPCs leak comment content, author identity, |
No comments yet