Authorization Flaw in Penpot Open-Source Design Platform
CVE-2026-105695
5.9MEDIUM
What is CVE-2026-105695?
Penpot, an open-source design and prototyping platform, has a vulnerability in its handling of user upload sessions. Prior to version 2.18.0, the 'assemble-chunks' function retrieves an upload session solely using its session ID, failing to properly scope this action to the authenticated user's profile. This allows an attacker who has obtained another user's completed upload-session UUID to assemble the victim's upload chunks into their own project, which could lead to unauthorized data exposure. Additionally, the attacker could delete the victim's pending upload session. This vulnerability has been addressed in version 2.18.0.
Affected Version(s)
penpot < 2.18.0
