CVE-2026-105695

MEDIUM CVSS 3.1: 5.9 EPSS 0.30%
Updated Oct 06, 2026
Penpot
Parameter Value
CVSS 5.9 (MEDIUM)
Fixed In 2.18.0
Type CWE-862 (Missing Authorization)
Vendor Penpot
Public PoC No

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session.

This issue is fixed in version 2.18.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1