CVE-2026-100868 PUBLISHED

Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor penpot
Product penpot
Versions Default: unaffected
  • affected from 0 to 2.18.0 (excl.)
Vendor penpot
Product @penpot/mcp
Versions Default: unaffected
  • affected from 0 to 2.15.4 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Binding to an Unrestricted IP Address CWE