CVE-2026-17613
CVE-2026-17613
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
| Vendor | penpot |
| Product | penpot |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for penpot penpot
Be the first to know when new unknown vulnerabilities affecting penpot penpot are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Penpot / Penpot
0 ≤ 2.17.0