Penpot · Penpot · CVE-2026-105690
**Name of the Vulnerable Software and Affected Versions**
Penpot versions prior to 2.18.0
**Description**
Logout functionality clears the browser's `auth-token` cookie but fails to revoke the corresponding server-side session. This allows a previously captured session token to remain valid and be used to make authenticated requests with the victim's authority until the session naturally expires.
**Recommendations**
Update to version 2.18.0.