---
id: CVE-2026-105692
title: Penpot is an open-source design and prototyping platform
summary: >-
  Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the
  delete-share-link RPC retrieves a caller-selected share-link ID and verifies
  only that the caller can edit the parent file. It does not verify that the
  caller…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-284
  - CWE-639
vendor: penpot
product: penpot
affected:
  - penpot < 2.18.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:19.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105692'
references:
  - url: >-
      https://github.com/penpot/penpot/commit/209aea83658f209c4189b531eeda0f3a638a0294
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/pull/11290'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/releases/tag/2.18.0'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/security/advisories/GHSA-8257-pm4f-cfhq'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T20:32:56.652Z'
---

## Overview

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
