« Volver al listado

Kaleidos

Kaleidos Penpot: vulnerabilidades y CVE

Kaleidos Penpot tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses8
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100868Media (5.3)0.26%—27 sept 2026
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to…
CVE-2026-47666Alta (7.6)0.35%—26 ago 2026
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a…
CVE-2026-47665Alta (8.7)0.45%—26 ago 2026
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and…
CVE-2026-17613Alta (7.5)0.61%—5 ago 2026
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full…
CVE-2026-45806Alta (7.7)0.35%—15 jul 2026
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend…
CVE-2026-45805Alta (8.8)0.38%—15 jul 2026
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute…
CVE-2026-44986Crítica (9.9)0.52%—15 jul 2026
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj…
CVE-2026-26202Alta (7.5)0.57%—19 feb 2026
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1059.007 JavaScript2
  3. T1189 Drive-by Compromise2
  4. T1190 Exploit Public-Facing Application2
  5. T1005 Data from Local System1
  6. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.