{"id":"CVE-2026-100868","title":"Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode","summary":"Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the P…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-1327"],"vendor":"penpot","product":"penpot","affected":["penpot < 2.18.0","@penpot/mcp <= 2.15.4"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T13:16:37.960","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100868","references":[{"url":"https://github.com/penpot/penpot","label":"disclosure@vulncheck.com"},{"url":"https://github.com/penpot/penpot/blob/1d2c37e52c733f74017d90b0fd1ae2d074a5c33d/mcp/packages/server/src/PluginBridge.ts#L52","label":"disclosure@vulncheck.com"},{"url":"https://github.com/penpot/penpot/commit/b5274a44766d095247037be18c1d1918ac67ddeb","label":"disclosure@vulncheck.com"},{"url":"https://github.com/penpot/penpot/security/advisories/GHSA-22qr-rp27-j9wm","label":"disclosure@vulncheck.com"},{"url":"https://github.com/penpot/penpot/security/advisories/GHSA-ch2q-6x56-qg5r","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/penpot-before-2.18.0-unauthenticated-websocket-access-via-mcp-bridge","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T13:53:26.573Z","slug":"CVE-2026-100868","body":"## Overview\n\nPenpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}