PT-2026-106216 · Penpot · Penpot

·

CVE-2026-105695

·

Published

2026-10-05

·

Updated

2026-10-06

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Penpot versions prior to 2.18.0
Description An issue exists where the assemble-chunks endpoint retrieves an upload session using only its session ID, failing to scope the lookup to the authenticated profile as the upload-chunk endpoint does. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into their own file, team font, or project import. This leads to the disclosure of the uploaded bytes and the deletion of the victim's pending session.
Recommendations Update to version 2.18.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105695

Affected Products

Penpot