penpot penpot是penpot公司开源的一款开源的设计和原型制作平台。 Penpot 2.15.0之前版本存在服务端请求伪造漏洞,该漏洞源于远程图片导入功能将用户控制的URL传递给后端RPC方法,且共享HTTP客户端未进行目标过滤,允许经过身份验证的文件编辑器访问内部端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44986 | 9.9 CRITICAL | Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-pr |
| CVE-2026-45805 | 8.8 HIGH | Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE |
No comments yet