CVE-2026-105694
MEDIUM
5,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c
https://github.com/penpot/penpot/pull/10989
https://github.com/penpot/penpot/pull/11044
https://github.com/penpot/penpot/releases/tag/2.18.0
https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4
https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2