Impact
Penpot versions up to 2.14.3 store comment text without sanitizing characters that are later rendered with innerHTML. This flaw allows an attacker to embed arbitrary JavaScript or HTML fragments in a comment, which is executed in the browsers of every collaborator when the comment panel is opened. The attack is passive; it can hijack session cookies, perform actions on behalf of the user, and provide access to files and projects on the Penpot origin.
Affected Systems
All Penpot deployments running 2.14.3 or earlier are affected. Updating to 2.15.3 or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that any team member with permission to post comments can embed malicious content, and any collaborator who views the comment panel will trigger script execution. The exploitation requires no special privileges beyond commenting rights, making it relatively easy to deploy once the environment is accessible.
OpenCVE Enrichment