Sceawere
Vulnerability Detail
CVE-2026-105690UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Penpot Insufficient Session Invalidation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 1h ago
- Vendor
- penpot
- Product
- penpot
- Attack Type
- CWE-613: Insufficient Session Expiration
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-05T20:17:18.943Z",
"pubdate": "2026-10-05T20:17:18.943Z",
"executiveSummary": "The vulnerability identified in Penpot involves a failure to properly invalidate server-side authentication sessions upon user logout.\nPrior to version 2.18.0, the application only performs client-side clearing of the authentication token cookie, leaving the corresponding session identifier active and valid on the server.\nThis flaw constitutes an insufficient session expiration vulnerability, which allows an attacker who has previously intercepted a valid session token to maintain unauthorized access to the victim's account even after the user has explicitly terminated their session.\nThe impact is significant, as it grants attackers the ability to perform authenticated actions on behalf of the victim until the session reaches its natural expiration time.\nThis vulnerability affects Penpot versions prior to 2.18.0.\nThe risk is elevated because the exploitation does not require active interaction from the user after the initial token interception, posing a persistent threat to session integrity in environments where traffic may be intercepted or tokens leaked.",
"technicalDetails": "The root cause of this vulnerability lies in an incomplete logout mechanism that fails to trigger a server-side session termination procedure.\nIn Penpot versions prior to 2.18.0, the logout process is implemented solely through client-side state manipulation—specifically, the deletion or clearing of the auth-token browser cookie.\nBecause the server-side session state is not updated or invalidated within the application's backend session management store, the backend continues to recognize and accept the existing session identifier as authoritative for subsequent API requests.\nAn attacker can exploit this by capturing a valid session token during the user's active session, utilizing techniques such as man-in-the-middle (MITM) attacks on unencrypted connections, cross-site scripting (XSS), or physical access to local browser storage.\nOnce the victim performs a logout action, the browser correctly clears the cookie; however, the session identifier remains 'live' in the server's session registry.\nAn attacker in possession of the intercepted token can manually inject it back into their own browser's session headers or utilize it directly in forged HTTP requests.\nSince the server-side state has not been destroyed, the application proceeds to process these requests as authenticated, bypassing the intended security controls of the logout functionality.\nThis creates a window of opportunity that spans the entire duration of the session's natural lifetime, during which the attacker maintains full authenticated access to the victim's account, resources, and sensitive design data within Penpot.\nThe vulnerability persists until the server-side session expires according to its configured time-to-live (TTL) settings or is invalidated by other means, effectively negating the security assurance typically provided by a standard logout function.\nThe scope of impact is restricted to the specific session duration but remains a critical flaw for multi-user design collaboration platforms where unauthorized access can lead to significant intellectual property loss or unauthorized modifications."
}