🔐 CVE Alert

CVE-2026-17613

UNKNOWN 0.0

CVE-2026-17613

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.

Vendor penpot
Product penpot
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for penpot penpot

Be the first to know when new unknown vulnerabilities affecting penpot penpot are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Penpot / Penpot
0 ≤ 2.17.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/penpot/penpot/releases/tag/2.17.0 penpot.app: https://penpot.app/ vokecyber.com: https://vokecyber.com/blog/cve-2026-17613-penpot-cross-team-file-takeover vokecyber.com: https://vokecyber.com/research/cve-2026-17613-penpot-cross-team-file-takeover