Unrestricted Link Sharing Vulnerability in Penpot Open-Source Design Platform
CVE-2026-105693

5.3MEDIUM

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105693?

Penpot, an open-source design and prototyping platform, has a vulnerability that allows unauthenticated users to access sensitive data. Before version 2.18.0, the platform's get-view-only-bundle RPC method leaked all share-link rows associated with a file, regardless of the user's authentication level. A user with a limited share link could exploit this by obtaining secret IDs and permissions of other links, gaining unauthorized access to page data outside of their intended scope. This issue has been addressed in the release of version 2.18.0.

Affected Version(s)

penpot < 2.18.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.