Stored Cross-Site Scripting Vulnerability in Penpot Design Platform
CVE-2026-47665
8.7HIGH
What is CVE-2026-47665?
Penpot, an open-source design and prototyping platform, is exposed to a stored cross-site scripting vulnerability in versions up to and including 2.14.3. This issue occurs through file comments that are stored as raw text and rendered on the page using innerHTML without any proper sanitization. Consequently, a malicious user can embed HTML, such as a script or error handler, into comments, which then get executed in the browsers of all collaborators accessing the same file. The result of this attack can include exploitation of session cookies, performing unauthorized actions, and accessing sensitive files and projects. This vulnerability has been addressed in version 2.15.3.
Affected Version(s)
penpot < 2.15.3
