WebSocket Bridge Vulnerability in Penpot by Penpot Team
CVE-2026-100868
5.3MEDIUM
What is CVE-2026-100868?
Penpot versions prior to 2.18.0 exhibit a significant security flaw wherein the MCP server plugin's WebSocket bridge is accessible without authentication across all network interfaces in single-user mode. This vulnerability allows unauthenticated actors on adjacent networks to connect to the WebSocket port. Once connected, attackers could impersonate the Penpot browser plugin, capture task payloads, and deliver fabricated responses to the MCP client, posing severe risks to the integrity of data and user operations.
Affected Version(s)
@penpot/mcp 0 <= 2.15.4
penpot 0 < 2.18.0
