CVE-2026-105690Medium· 5.9▾ SunlitPenpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105694Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105696Medium· 6.5Penpot is an open-source design and prototyping platform
CVE-2026-105695Medium· 5.9Penpot is an open-source design and prototyping platform
CVE-2026-105691Critical· 9.9Penpot is an open-source design and prototyping platform
CVE-2026-105692Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105693Medium· 5.3Penpot is an open-source design and prototyping platform