Sceawere
Vulnerability Detail
CVE-2026-100868UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Penpot Unauthenticated MCP WebSocket Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 19h ago
- Vendor
- penpot
- Product
- penpot
- Attack Type
- Binding to an Unrestricted IP Address
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-27T13:16:37.960Z",
"pubdate": "2026-09-27T13:16:37.960Z",
"executiveSummary": "A critical security vulnerability exists in Penpot versions prior to 2.18.0 concerning the Model Context Protocol (MCP) server plugin.\nThe vulnerability involves the insecure binding of the WebSocket bridge to all network interfaces without requiring authentication while operating in single-user mode.\nThis flaw exposes the system to unauthorized access by any entity on an adjacent network, bypassing intended security boundaries.\nSuccessful exploitation allows an attacker to masquerade as the legitimate Penpot browser plugin, intercept sensitive task payloads, and inject malicious or forged data back into the MCP client ecosystem.\nThe risk is severe as it enables arbitrary interaction with the MCP service, potentially leading to unauthorized data manipulation or unauthorized command execution within the context of the user's workflow.\nNo authentication is required for an attacker to establish a connection, making the system vulnerable to any network-adjacent actor.",
"technicalDetails": "The root cause of the vulnerability lies in the socket configuration of the Penpot MCP server plugin. By default, the application binds the WebSocket listener to '0.0.0.0' or all available network interfaces rather than restricting access to the loopback address ('127.0.0.1').\nIn single-user mode, the architecture relies on the implicit trust of local connections; however, by exposing this port to the network stack, Penpot effectively widens the attack surface to any device sharing the local broadcast or routed network segment.\nThe exploitation flow proceeds as follows: 1) An unauthenticated attacker probes the network for the specific WebSocket port utilized by the Penpot MCP bridge. 2) Upon identifying an open listener, the attacker initiates a standard WebSocket handshake with the server. 3) Because the service lacks an authentication handshake or cryptographic identity verification, the server treats the attacker's connection as a legitimate client/plugin interaction.\nOnce the session is established, the attacker assumes the role of the authorized browser plugin. This allows the attacker to perform Man-in-the-Middle (MitM) or full impersonation attacks. The attacker can then subscribe to task streams, intercepting sensitive project data or operational payloads sent by the MCP client.\nFurthermore, the attacker can transmit forged payloads back to the MCP client. Since the client trusts the WebSocket bridge's output, it processes the forged results as valid, which could result in data corruption, manipulation of the user's workspace, or potentially triggering secondary vulnerabilities within the client-side parsing logic.\nThe vulnerability affects all versions of Penpot prior to 2.18.0. The lack of access control lists (ACLs) or authentication tokens at the WebSocket protocol level means that any adjacent attacker can maintain persistent or intermittent access to the MCP bridge without triggering alerts in standard monitoring systems.\nThe post-exploitation impact is high, as the attacker effectively bypasses the application's local-only security model, gaining the ability to subvert the integrity of the information flow between the MCP client and the Penpot backend."
}