CVE-2026-100868
MEDIUM
5,3
Source: [email protected]
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,3
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: low
Description
AI Translation Available
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
1327
Binding to an Unrestricted IP Address
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Applicable Platforms
Languages:
Other
Technologies:
Web Server, Client Server, Cloud Computing
https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r
https://github.com/penpot/penpot
https://github.com/penpot/penpot/blob/1d2c37e52c733f74017d90b0fd1ae2d074a5c33d/…
https://github.com/penpot/penpot/commit/b5274a44766d095247037be18c1d1918ac67ddeb
https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm
https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r
https://www.vulncheck.com/advisories/penpot-before-2.18.0-unauthenticated-webso…