Impact
Penpot up to version 2.14.3 is affected by a stored cross‑site scripting vulnerability. Custom font‑family names are injected directly into a @font‑face style rule without sanitization, allowing a malicious font name to break out of the style element and execute arbitrary JavaScript when the file is rendered. This can lead to theft of session cookies and impersonation of the user on the Penpot origin.
Affected Systems
The vulnerable software is Penpot by Penpot. Versions up to and including 2.14.3 are compromised. The issue is fixed in 2.15.3 and later.
Risk and Exploitability
The CVSS base score is 7.6, indicating a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of exploitation in the wild. However, the attack requires that a user open a file containing a malicious font name. Because the payload runs in the Penpot origin, it can steal cookies and perform unauthorized actions. The vulnerability is therefore moderate to high risk for organizations where multiple users collaborate on shared projects.
OpenCVE Enrichment