Stored Cross-Site Scripting Vulnerability in Penpot Design Platform
CVE-2026-47665

8.7HIGH

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-47665?

Penpot, an open-source design and prototyping platform, is exposed to a stored cross-site scripting vulnerability in versions up to and including 2.14.3. This issue occurs through file comments that are stored as raw text and rendered on the page using innerHTML without any proper sanitization. Consequently, a malicious user can embed HTML, such as a script or error handler, into comments, which then get executed in the browsers of all collaborators accessing the same file. The result of this attack can include exploitation of session cookies, performing unauthorized actions, and accessing sensitive files and projects. This vulnerability has been addressed in version 2.15.3.

Affected Version(s)

penpot < 2.15.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.