CVE-2026-105696
Deferred Deferred - Pending Action

Information Disclosure in Penpot Design Platform

Vulnerability report for CVE-2026-105696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Penpot, an open-source design platform. It allows authenticated users with a share link to access pages in a file that were not included in the share link's authorized scope. The issue occurs because the get-page and get-file-fragment RPC commands do not properly validate whether the requested page belongs to the authorized set defined by the share link.

Detection Guidance

To detect this vulnerability, check if your Penpot instance is running a version prior to 2.18.0. Use commands like 'curl -s https://your-penpot-instance/api/version' or check the version in the application settings. If the version is below 2.18.0, the system is vulnerable.

Impact Analysis

If you use Penpot's share-link feature, an attacker with a valid share link and their own authenticated session could access design data from pages you intended to keep private. This includes viewing full shape and design details of unauthorized pages if the attacker knows the page identifier.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive design data, potentially violating data protection requirements under GDPR or HIPAA if such data is considered protected information. It undermines intended access controls and may result in non-compliance with privacy and confidentiality obligations.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later immediately. This version includes fixes for the get-page and get-file-fragment RPC commands to enforce page scope validation. No additional configuration changes are required beyond the upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart