Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
Published: 2026-10-05
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to user uploads and deletion of pending sessions
Action: Patch immediately
AI Analysis

Impact

Penpot’s assemble-chunks endpoint dereferences an upload session solely by its UUID, while the upload-chunk operation correctly associates the session with the authenticated user. This missing authorization check allows a logged‑in attacker to supply another user’s live, completed upload-session UUID and causes the server to assemble the victim’s uploaded chunks into the attacker’s own file, team font, or project import. The attacker thereby gains read access to arbitrary uploaded data and can delete the victim’s pending session, potentially disrupting the victim’s workflow.

Affected Systems

The vulnerability affects all Penpot deployments running a version earlier than 2.18.0. The product is Penpot, and the CNA identifies the affected vendor/product as penpot:penpot.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker must be authenticated and must know or guess another user’s active upload-session UUID, which can be discovered through normal application usage. Once the attacker obtains a valid UUID, the exploit is straightforward, requiring only a crafted request to the assemble-chunks API. Because the vulnerability permits data disclosure and session deletion, the impact is significant for organizations that rely on Penpot for secure design collaboration.

Generated by OpenCVE AI on October 5, 2026 at 21:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Penpot to version 2.18.0 or later to ensure the assemble-chunks endpoint validates session ownership.
  • Restrict access to the assemble-chunks API so that only requests authenticated as the session owner are honored, and audit endpoints regularly for cross‑user activity.
  • If immediate upgrade is not possible, remove or obfuscate publicly exposed upload-session UUIDs and clear pending sessions after a defined inactivity period to limit the window of exploitation.

Generated by OpenCVE AI on October 5, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Penpot
Penpot penpot
Vendors & Products Penpot
Penpot penpot

Mon, 05 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
Title Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T20:40:42.567Z

Reserved: 2026-10-05T17:48:58.627Z

Link: CVE-2026-105695

cve-icon Vulnrichment

Updated: 2026-10-05T20:40:18.735Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T20:17:20.017

Modified: 2026-10-05T21:16:34.983

Link: CVE-2026-105695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:30:19Z

Weaknesses