Media Upload Vulnerability in Penpot Open-Source Design Platform
CVE-2026-105686
What is CVE-2026-105686?
Penpot, an open-source design and prototyping platform, contains a vulnerability in its chunked media upload functionality. Prior to version 2.18.0, the platform fails to adequately handle validation of upload indices. This allows authenticated users to repeatedly upload media using the same valid index without the system rejecting or overwriting previously stored objects. As a result, each valid upload request can lead to the creation of additional temporary objects, potentially exceeding the declared logical size of the upload session. This inconsistency in chunk count is only detected post-allocation, leading to increased storage use and resource strain. The issue has been addressed in the release of version 2.18.0, which resolves this vulnerability.
Affected Version(s)
penpot < 2.18.0
