Impact
A flaw in the Penpot design platform allows a holder of a share‑link to read the full shape and design data of pages in the same file that are not part of the link’s authorized scope. The get‑page RPC accepts a page identifier without verifying it belongs to the share‑link’s permitted set, and the call requires an authenticated session. An attacker who possesses both a valid share link and their own authenticated account can therefore retrieve confidential design information that was not meant for them. The vulnerability is a classic access‑control weakness (CWE‑862) that leads to unauthorized data disclosure.
Affected Systems
The affected product is Penpot. All releases prior to version 2.18.0 are vulnerable; the issue is fixed in release 2.18.0 and later.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to have both a share link and an active authenticated session; the exploit is therefore observed in environments where share links are routinely given to users. Once exploited, the attacker can read any page data for which they know the identifier, resulting in sensitive information exposure. Given the moderate CVSS and lack of known exploitability data, the risk is considered medium, but should be addressed promptly to prevent potential leakage of design assets.
OpenCVE Enrichment