Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-05 15:16
Updated : 2026-09-03 17:45
NVD link : CVE-2026-17613
Mitre link : CVE-2026-17613
CVE.ORG link : CVE-2026-17613
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
