CVE-2026-105693

MEDIUM CVSS 3.1: 5.3 EPSS 0.22%
Updated Oct 06, 2026
Penpot
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 2.18.0
Type CWE-862 (Missing Authorization)
Vendor Penpot
Public PoC No

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share.

This issue is fixed in version 2.18.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1