CVE-2026-17613

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 15:16

Updated : 2026-09-03 17:45


NVD link : CVE-2026-17613

Mitre link : CVE-2026-17613

CVE.ORG link : CVE-2026-17613


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization