PT-2026-82331 · Penpot · Penpot

·

CVE-2026-47665

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Penpot versions prior to 2.15.3
Description Stored cross-site scripting occurs when file comments are stored as raw text and rendered into the page using innerHTML without sanitization. The backend only performs a length check, allowing a team member to embed HTML or scripts within a comment. When other collaborators open the comments panel, the script executes on the Penpot origin, which can lead to the theft of session cookies, unauthorized actions performed as the victim, and unauthorized access to files and projects.
Recommendations Update to version 2.15.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47665
GHSA-VC72-6R45-Q988

Affected Products

Penpot