CVE-2026-105690
Deferred Deferred - Pending Action

Session Token Persistence After Logout in Penpot

Vulnerability report for CVE-2026-105690, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Penpot involves improper session management where logging out does not invalidate the server-side session. When a user logs out, only the client-side auth-token cookie is cleared, while the server retains the active session. This allows an attacker who has captured the session cookie to continue accessing the victim's full profile even after logout.

Detection Guidance

To detect this vulnerability, check if Penpot server sessions remain active after logout. Inspect browser cookies for lingering auth-token values post-logout. Monitor server logs for continued activity under a user's session ID after logout events.

Impact Analysis

If you use Penpot on a shared device, an attacker could capture your session cookie and access your account even after you log out. This could lead to unauthorized access to your designs, data, or profile until the session naturally expires.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized access to sensitive data, violating principles of data minimization and access control required by GDPR and HIPAA. Organizations using Penpot must ensure proper session management to meet these regulatory requirements.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later to fix the session invalidation issue. Ensure server-side sessions are properly revoked upon logout. Review and update logout mechanisms to invalidate all active sessions for the user.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105690. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart