Impact
An authenticated user can invoke Penpot’s import-binfile RPC without proper authorization on the file-id parameter, enabling them to overwrite any file on the server. The same RPC also allows the user to subscribe to WebSocket events, giving full visibility into server data and providing a path for data poisoning. This weakness corresponds to improper access control and can compromise confidentiality, integrity, and availability of any file chosen by the attacker.
Affected Systems
The vulnerability affects installations of the Penpot design and prototyping platform. Versions prior to the fix released in 2.17.0 are impacted; no explicit version range is listed, so all unpatched Penpot environments are considered exposed.
Risk and Exploitability
With a CVSS score of 7.5, the flaw is classified as medium‑to‑high severity. The vulnerability permits any authenticated user to overwrite arbitrary files on the server and subscribe to WebSocket events, giving full data exfiltration capability. No EPSS score is available, and it is not listed in CISA’s KEV catalog. The lack of additional controls means the risk remains significant for any environment where the import‑binfile RPC is reachable to authenticated users.
OpenCVE Enrichment