Authentication Bypass in Penpot Open-source Design Platform
CVE-2026-105696

6.5MEDIUM

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105696?

Penpot, an open-source design and prototyping platform, has a vulnerability that allows an attacker to exploit the get-page RPC method. Prior to version 2.18.0, the method accepts a share-link permission object that grants blanket read access. However, it fails to validate that the page-id provided by the caller corresponds to the authorized pages within the link. As a result, if an attacker possesses a valid share link and is authenticated in Penpot, they can access complete design and shape data of any page in the same document, given they know the page identifier. The get-file-fragment RPC method also poses similar risks, allowing unauthorized access to shared files. This issue is addressed in version 2.18.0.

Affected Version(s)

penpot < 2.18.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.