Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kairos-T

#50432of 57,584
5.4Total CVSS
Vulnerabilities · 1
PT-2026-106215
5.4
2026-10-05
Penpot · Penpot · CVE-2026-105694
**Name of the Vulnerable Software and Affected Versions** Penpot versions prior to 2.18.0 **Description** Authenticated users with file-edit permissions can upload SVG media containing scripts, event-handler attributes, and `foreignObject` elements that are stored without sanitization and served as `image/svg+xml` from the Penpot origin. A victim navigating to the asset URL may execute attacker-controlled JavaScript within that origin, enabling requests and data access using the victim's session authority. **Recommendations** Update to version 2.18.0.