All 8 CVE vulnerabilities found in penpot, with AI-generated Chinese analysis, references, and POCs.
Vendor: penpot
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-100868 | Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge CWE-1327 | 6.3 | Medium | 2026-09-27 |
| CVE-2026-47665 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML CWE-79 | 8.7 | High | 2026-08-26 |
| CVE-2026-47666 | Penpot: Stored XSS via custom font family name injected into a @font-face style rule CWE-79 | 7.6 | High | 2026-08-26 |
| CVE-2026-17613 | CVE-2026-17613 | - | - | 2026-08-05 |
| CVE-2026-45805 | Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE CWE-749 | 8.8 | High | 2026-07-15 |
| CVE-2026-44986 | Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile CWE-287 | 9.9 | Critical | 2026-07-15 |
| CVE-2026-45806 | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url CWE-918 | 7.7 | High | 2026-07-15 |
| CVE-2026-26202 | Penpot has Arbitrary File Read via create-font-variant RPC endpoint CWE-22 | 7.5 | High | 2026-02-19 |
All 8 known CVE vulnerabilities affecting penpot with full Chinese analysis, references, and POCs where available.