CVE-2026-105684
Deferred Deferred - Pending Action

Authentication Bypass in Penpot Design Platform

Vulnerability report for CVE-2026-105684, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Penpot (CVE-2026-105684) involves improper authorization checks in comment-related RPC commands. The get-comment-threads, get-comment-thread, and get-comments functions do not respect page-scoped share link restrictions. Attackers with a share link for one page can access comments, user details (names, emails, photos), and page IDs from all pages in the same file.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Use commands like 'curl -s https://your-penpot-instance.com/api/version' or inspect the version in the application settings. Verify if share links grant access to comments across all pages rather than just the intended page.

Impact Analysis

An attacker could view sensitive comments and user identities across all pages in a file, even those not shared. They could also enumerate page IDs and use them to extract full page content via other RPCs, leading to unauthorized data exposure.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal data (user emails, photos) and sensitive design content, violating GDPR (data protection) and HIPAA (health information privacy) requirements for access controls and data minimization.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. Review and revoke any existing share links to ensure they are not exposing sensitive comment data. Monitor for unusual access patterns or data exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105684. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart