---
id: CVE-2026-105694
title: Penpot is an open-source design and prototyping platform
summary: >-
  Penpot is an open-source design and prototyping platform. Prior to 2.18.0,
  authenticated users with file-edit permission can upload SVG media whose
  scripts, event-handler attributes, and foreignObject elements are stored
  without sanitiza…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: penpot
product: penpot
affected:
  - penpot < 2.18.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:19.973'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105694'
references:
  - url: >-
      https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98c
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/pull/10989'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/pull/11044'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/releases/tag/2.18.0'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T20:32:56.653Z'
---

## Overview

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
