← Back to CVE List
CVE-2026-105695NVD
Vulnerability Summary
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
CVSS v3.1 Base Metrics — Score 5.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityLow
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/penpot/penpot/commit/367e4d534c536c33d4f3fbad375f3e9c29b787a6
- https://github.com/penpot/penpot/pull/11012
- https://github.com/penpot/penpot/releases/tag/2.18.0
- https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv
- https://github.com/penpot/penpot/security/advisories/GHSA-5vrm-3c6w-gjfv