penpot penpot是penpot公司开源的一款开源的设计和原型制作平台。 Penpot 2.15.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于CWE-749(权限许可和访问控制问题),可能允许网络上的任何人执行服务器上的JavaScript代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: unauthenticated /execute on 0.0.0.0:4403 executed arbitrary JS as uid=0 flag=PROOF_0730922deaa80032 and exfiltrated proof token from /flag.txt
| CVE-2026-44986 | 9.9 CRITICAL | Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-pr |
| CVE-2026-45806 | 7.7 HIGH | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url |
No comments yet