CVE-2026-105694: medium-severity vulnerability in penpot
Penpot: Stored XSS via Unsanitised SVG Uploads
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
penpot · penpotRelated CVEs — penpot
In the same product, most dangerous first.
CVE-2026-26202HIGHPenpot has Arbitrary File Read via create-font-variant RPC endpointEPSS 0.6%CVE-2026-44986CRITICALPenpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profileEPSS 0.5%CVE-2026-47665HIGHPenpot: Stored XSS via comment content, innerHTML renders unsanitized HTMLEPSS 0.4%CVE-2026-45805HIGHPenpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCEEPSS 0.4%CVE-2026-105691CRITICALPenpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-colorEPSS 0.4%CVE-2026-45806HIGHPenpot: Authenticated SSRF in remote image import via create-file-media-object-from-urlEPSS 0.4%
References
https://github.com/penpot/penpot/commit/c4dd04353fcf06c3e10a64e3d8e43945508ae98chttps://github.com/penpot/penpot/pull/10989https://github.com/penpot/penpot/pull/11044https://github.com/penpot/penpot/releases/tag/2.18.0https://github.com/penpot/penpot/security/advisories/GHSA-wrcr-m7p8-m2c4https://github.com/penpot/penpot/security/advisories/GHSA-xg6f-5v5x-g4w2