CVE-2026-105687Medium· 4.9▾ SunlitPenpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105688Medium· 6.7Penpot is an open-source design and prototyping platform
CVE-2026-105684Medium· 4.3Penpot is an open-source design and prototyping platform
CVE-2026-105694Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105696Medium· 6.5Penpot is an open-source design and prototyping platform
CVE-2026-105695Medium· 5.9Penpot is an open-source design and prototyping platform
CVE-2026-105691Critical· 9.9Penpot is an open-source design and prototyping platform