CVE-2026-17613 PUBLISHED

CVE-2026-17613

Assigner: certcc
Reserved: 27.07.2026 Published: 05.08.2026 Updated: 05.08.2026

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.

Product Status

Vendor Penpot
Product Penpot
Versions
  • affected from 0 to 2.17.0 (incl.)

References

Problem Types

  • CWE-862 Missing Authorization