Authorization Flaw in Penpot Design Platform
CVE-2026-105692
5.4MEDIUM
What is CVE-2026-105692?
The Penpot design and prototyping platform features a vulnerability that enables any file editor to delete share links created by other users. This flaw arises because the delete-share-link RPC does not verify whether the requester is the creator of the share link or possesses the necessary owner or administrator rights. As a result, external reviewers' access can be revoked unknowingly by users familiar with the share-link UUID. The issue has been addressed in version 2.18.0 with enhanced verification checks.
Affected Version(s)
penpot < 2.18.0
