SSRF Vulnerability in Penpot Design and Prototyping Platform
CVE-2026-105689
What is CVE-2026-105689?
Penpot, an open-source design and prototyping platform, is vulnerable to a server-side request forgery issue in versions prior to 2.18.0. The vulnerability is rooted in the app.util.ssrf/blocked-address logic, which fails to properly handle NAT64, 6to4, or Teredo address types, coupled with insufficient CIDR checks for IPv4 addresses. An attacker could take advantage of this flaw by routing requests through a NAT64 gateway or by controlling a DNS AAAA record. This would enable the perpetrator to manipulate media import URLs or webhook URLs, allowing them to inject potentially malicious IPv6 transition addresses that could lead to exposure of sensitive data, such as response bodies from media imports or response statuses through webhook deliveries. This significant issue has been addressed in Penpot version 2.18.0.
Affected Version(s)
penpot < 2.18.0
