CVE-2026-105693
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| penpot | penpot | < 2.18.0 | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
References
- https://github.com/penpot/penpot/security/advisories/GHSA-w8mf-4x22-24gg
- https://github.com/penpot/penpot/commit/15195b3bbbbf2911b24007ad42453d264a2774d4
- https://github.com/penpot/penpot/releases/tag/2.18.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.