Unrestricted Link Sharing Vulnerability in Penpot Open-Source Design Platform
CVE-2026-105693
5.3MEDIUM
What is CVE-2026-105693?
Penpot, an open-source design and prototyping platform, has a vulnerability that allows unauthenticated users to access sensitive data. Before version 2.18.0, the platform's get-view-only-bundle RPC method leaked all share-link rows associated with a file, regardless of the user's authentication level. A user with a limited share link could exploit this by obtaining secret IDs and permissions of other links, gaining unauthorized access to page data outside of their intended scope. This issue has been addressed in the release of version 2.18.0.
Affected Version(s)
penpot < 2.18.0
