---
id: CVE-2026-105695
title: Penpot is an open-source design and prototyping platform
summary: >-
  Penpot is an open-source design and prototyping platform. Prior to 2.18.0,
  assemble-chunks retrieves an upload session using only its session ID, while
  upload-chunk correctly scopes the lookup to the authenticated profile. An
  authenticat…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L'
cwe:
  - CWE-862
vendor: penpot
product: penpot
affected:
  - penpot < 2.18.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T21:16:34.983'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105695'
references:
  - url: >-
      https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/pull/11012'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/releases/tag/2.18.0'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv'
    label: security-advisories@github.com
  - url: 'https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T20:40:35.188252Z'
ingestedAt: '2026-10-05T20:32:56.653Z'
---

## Overview

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
