๐Ÿ” CVE Alert

CVE-2026-105695

MEDIUM 5.9

Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.

CWE CWE-862
Vendor penpot
Product penpot
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for penpot penpot

Be the first to know when new medium vulnerabilities affecting penpot penpot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low

Affected Versions

penpot / penpot
< 2.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv github.com: https://github.com/penpot/penpot/pull/11012 github.com: https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6 github.com: https://github.com/penpot/penpot/releases/tag/2.18.0