Kaleidos
Kaleidos Penpot: vulnerabilidades y CVE
Kaleidos Penpot tiene 20 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses20
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-105696 | Media (6.5) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to… |
| CVE-2026-105695 | Media (5.9) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated… |
| CVE-2026-105694 | Media (5.4) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are… |
| CVE-2026-105693 | Media (5.3) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped… |
| CVE-2026-105692 | Media (5.4) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not… |
| CVE-2026-105691 | Crítica (9.9) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string… |
| CVE-2026-105690 | Media (5.9) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token… |
| CVE-2026-105689 | Media (6) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies… |
| CVE-2026-105688 | Media (6.7) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation… |
| CVE-2026-105687 | Media (4.9) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A… |
| CVE-2026-105686 | Media (5.3) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous… |
| CVE-2026-105684 | Media (4.3) | — | — | 5 oct 2026 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's… |
| CVE-2026-100868 | Media (5.3) | 0.26% | — | 27 sept 2026 | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to… |
| CVE-2026-47666 | Alta (7.6) | 0.35% | — | 26 ago 2026 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a… |
| CVE-2026-47665 | Alta (8.7) | 0.45% | — | 26 ago 2026 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and… |
| CVE-2026-17613 | Alta (7.5) | 0.61% | — | 5 ago 2026 | Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full… |
| CVE-2026-45806 | Alta (7.7) | 0.35% | — | 15 jul 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend… |
| CVE-2026-45805 | Alta (8.8) | 0.38% | — | 15 jul 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute… |
| CVE-2026-44986 | Crítica (9.9) | 0.52% | — | 15 jul 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj… |
| CVE-2026-26202 | Alta (7.5) | 0.57% | — | 19 feb 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.