Authentication Bypass in Penpot Open-source Design Platform
CVE-2026-105696
6.5MEDIUM
What is CVE-2026-105696?
Penpot, an open-source design and prototyping platform, has a vulnerability that allows an attacker to exploit the get-page RPC method. Prior to version 2.18.0, the method accepts a share-link permission object that grants blanket read access. However, it fails to validate that the page-id provided by the caller corresponds to the authorized pages within the link. As a result, if an attacker possesses a valid share link and is authenticated in Penpot, they can access complete design and shape data of any page in the same document, given they know the page identifier. The get-file-fragment RPC method also poses similar risks, allowing unauthorized access to shared files. This issue is addressed in version 2.18.0.
Affected Version(s)
penpot < 2.18.0
