Browse all 7 CVE security advisories affecting penpot. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-47665 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML — penpot CWE-79 | 8.7 | High | 2026-08-26 |
| CVE-2026-47666 | Penpot: Stored XSS via custom font family name injected into a @font-face style rule — penpot CWE-79 | 7.6 | High | 2026-08-26 |
| CVE-2026-17613 | CVE-2026-17613 — Penpot | - | - | 2026-08-05 |
| CVE-2026-45805 | Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE — penpot CWE-749 | 8.8 | High | 2026-07-15 |
| CVE-2026-44986 | Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile — penpot CWE-287 | 9.9 | Critical | 2026-07-15 |
| CVE-2026-45806 | Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url — penpot CWE-918 | 7.7 | High | 2026-07-15 |
| CVE-2026-26202 | Penpot has Arbitrary File Read via create-font-variant RPC endpoint — penpot CWE-22 | 7.5 | High | 2026-02-19 |
This page lists every published CVE security advisory associated with penpot. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.