← Back to CVE List
CVE-2026-105689NVD
Vulnerability Summary
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.
CVSS v4.0 Base Metrics — Score 6.0 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsPresent
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- penpot penpot >= < 2.18.0
Not provided by cveorg for this CVE.