CVE-2026-105694
Deferred Deferred - Pending Action

Stored XSS in Penpot via Unsanitized SVG Uploads

Vulnerability report for CVE-2026-105694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Penpot, an open-source design tool. Authenticated users with file-edit permissions can upload SVG files containing malicious scripts, event handlers, or foreignObject elements. These files are stored without sanitization and served as image/svg+xml from the Penpot origin. When a victim accesses the asset URL, the embedded JavaScript executes in the Penpot context, allowing the attacker to perform actions with the victim's session.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Inspect uploaded SVG files for malicious content like script tags, event handlers, or foreignObject elements. Use network monitoring to identify requests to asset URLs that may execute unauthorized scripts.

Impact Analysis

An attacker could steal sensitive data, perform actions on your behalf, or gain unauthorized access to your Penpot account. The impact depends on your permissions and the data accessible through your session. The vulnerability requires user interaction (opening the SVG) but can lead to high confidentiality impacts.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using Penpot may face compliance risks if user data is compromised through this flaw.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later. Ensure SVG files are sanitized during upload to remove scripts, event handlers, and foreignObject elements. Configure asset serving to include Content-Disposition: attachment headers to prevent direct browser rendering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart