CVE-2026-105695
Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
| CWE | CWE-862 |
| Vendor | penpot |
| Product | penpot |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for penpot penpot
Be the first to know when new medium vulnerabilities affecting penpot penpot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low
Affected Versions
penpot / penpot
< 2.18.0