CVE-2026-105691Critical· 9.9▾ MidnightPenpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.ex…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105694Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105696Medium· 6.5Penpot is an open-source design and prototyping platform
CVE-2026-105695Medium· 5.9Penpot is an open-source design and prototyping platform
CVE-2026-105692Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105693Medium· 5.3Penpot is an open-source design and prototyping platform
CVE-2026-105688Medium· 6.7Penpot is an open-source design and prototyping platform