Impact
Penpot’s assemble-chunks endpoint dereferences an upload session solely by its UUID, while the upload-chunk operation correctly associates the session with the authenticated user. This missing authorization check allows a logged‑in attacker to supply another user’s live, completed upload-session UUID and causes the server to assemble the victim’s uploaded chunks into the attacker’s own file, team font, or project import. The attacker thereby gains read access to arbitrary uploaded data and can delete the victim’s pending session, potentially disrupting the victim’s workflow.
Affected Systems
The vulnerability affects all Penpot deployments running a version earlier than 2.18.0. The product is Penpot, and the CNA identifies the affected vendor/product as penpot:penpot.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker must be authenticated and must know or guess another user’s active upload-session UUID, which can be discovered through normal application usage. Once the attacker obtains a valid UUID, the exploit is straightforward, requiring only a crafted request to the assemble-chunks API. Because the vulnerability permits data disclosure and session deletion, the impact is significant for organizations that rely on Penpot for secure design collaboration.
OpenCVE Enrichment