← Back to CVE List
CVE-2026-105691NVD
Vulnerability Summary
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
CVSS v3.1 Base Metrics — Score 9.9 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/penpot/penpot/commit/aa3bc1ae984577f0354d4270d2546e15985f4bcf
- https://github.com/penpot/penpot/pull/11272
- https://github.com/penpot/penpot/releases/tag/2.18.0
- https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86
- https://github.com/penpot/penpot/security/advisories/GHSA-4f36-m4hj-cv86