CVE-2026-105695Medium· 5.9▾ TwilightPoC availablePenpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticat…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 32.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105696Medium· 6.5Penpot is an open-source design and prototyping platform
CVE-2026-105693Medium· 5.3Penpot is an open-source design and prototyping platform
CVE-2026-105694Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105691Critical· 9.9Penpot is an open-source design and prototyping platform
CVE-2026-105692Medium· 5.4Penpot is an open-source design and prototyping platform
CVE-2026-105688Medium· 6.7Penpot is an open-source design and prototyping platform