Stored Cross-Site Scripting Vulnerability in Penpot by Kaleido
CVE-2026-47666

7.6HIGH

Key Information:

Vendor

Penpot

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-47666?

Penpot, an open-source design and prototyping platform by Kaleido, is susceptible to stored cross-site scripting in versions up to and including 2.14.3. This vulnerability arises from the backend's acceptance of arbitrary font-family strings, which are then processed and injected into the page as HTML through an unsafe method. If a team member accesses a file that references a maliciously crafted font, the injected script can execute on the Penpot origin, compromising user session context and enabling unauthorized actions on behalf of the affected user. This is a passive attack vector, whereby merely rendering the affected page triggers the exploit, leading to potential theft of session cookies and access to sensitive projects and files. The issue was resolved in version 2.15.3.

Affected Version(s)

penpot < 2.15.3

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.