WebSocket Bridge Vulnerability in Penpot by Penpot Team
CVE-2026-100868

5.3MEDIUM

Key Information:

Vendor

Penpot

Vendor
CVE Published:
27 September 2026

What is CVE-2026-100868?

Penpot versions prior to 2.18.0 exhibit a significant security flaw wherein the MCP server plugin's WebSocket bridge is accessible without authentication across all network interfaces in single-user mode. This vulnerability allows unauthenticated actors on adjacent networks to connect to the WebSocket port. Once connected, attackers could impersonate the Penpot browser plugin, capture task payloads, and deliver fabricated responses to the MCP client, posing severe risks to the integrity of data and user operations.

Affected Version(s)

@penpot/mcp 0 <= 2.15.4

penpot 0 < 2.18.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.