Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure via Access Control Bypass
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Penpot design platform allows a holder of a share‑link to read the full shape and design data of pages in the same file that are not part of the link’s authorized scope. The get‑page RPC accepts a page identifier without verifying it belongs to the share‑link’s permitted set, and the call requires an authenticated session. An attacker who possesses both a valid share link and their own authenticated account can therefore retrieve confidential design information that was not meant for them. The vulnerability is a classic access‑control weakness (CWE‑862) that leads to unauthorized data disclosure.

Affected Systems

The affected product is Penpot. All releases prior to version 2.18.0 are vulnerable; the issue is fixed in release 2.18.0 and later.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to have both a share link and an active authenticated session; the exploit is therefore observed in environments where share links are routinely given to users. Once exploited, the attacker can read any page data for which they know the identifier, resulting in sensitive information exposure. Given the moderate CVSS and lack of known exploitability data, the risk is considered medium, but should be addressed promptly to prevent potential leakage of design assets.

Generated by OpenCVE AI on October 5, 2026 at 21:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Penpot version 2.18.0 or later, which removes the authorization check in get‑page and get‑file‑fragment RPCs.
  • Ensure that share links are created with the minimum required permissions and avoid granting read access to users who do not need to view the entire file.
  • Review and limit the distribution of share links to trusted collaborators, and monitor for usage patterns that deviate from expected behavior.

Generated by OpenCVE AI on October 5, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Penpot
Penpot penpot
Vendors & Products Penpot
Penpot penpot

Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0.
Title Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the link's authorized scope via the get-page RPC command
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T20:05:30.908Z

Reserved: 2026-10-05T17:48:58.627Z

Link: CVE-2026-105696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T20:17:20.240

Modified: 2026-10-05T20:17:20.423

Link: CVE-2026-105696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:30:19Z

Weaknesses