Penpot · Penpot · CVE-2026-105694
**Name of the Vulnerable Software and Affected Versions**
Penpot versions prior to 2.18.0
**Description**
Authenticated users with file-edit permissions can upload SVG media containing scripts, event-handler attributes, and `foreignObject` elements that are stored without sanitization and served as `image/svg+xml` from the Penpot origin. A victim navigating to the asset URL may execute attacker-controlled JavaScript within that origin, enabling requests and data access using the victim's session authority.
**Recommendations**
Update to version 2.18.0.