Sceawere

Vulnerability Detail

CVE-2026-105691UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Penpot SVG Export Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
1h ago
Vendor
penpot
Product
penpot
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-10-05T20:17:19.137Z",
  "pubdate": "2026-10-05T20:17:19.137Z",
  "executiveSummary": "A critical command injection vulnerability exists in Penpot prior to version 2.18.0, stemming from improper neutralization of user-supplied input during the SVG export process.\nThe vulnerability allows an attacker with file editing capabilities or access to a public share link to inject arbitrary shell metacharacters into an SVG object's fill-color attribute.\nWhen the SVG exporter processes this object, the malicious input is concatenated into a system command executed via child_process.exec.\nSuccessful exploitation results in Remote Code Execution (RCE) with the privileges of the exporter service, potentially leading to full system compromise, data exfiltration, or lateral movement within the infrastructure.\nThe flaw affects the platform's ability to safely sanitize design metadata before passing it to backend system utilities.\nThe risk is exacerbated by the fact that the exploit can be triggered via public-facing share links, significantly increasing the attack surface to unauthenticated actors.",
  "technicalDetails": "The vulnerability resides within the Penpot SVG exporter component, specifically in how the application handles the translation of object fill-color properties into internal system commands.\nThe root cause is an insecure implementation of a function that constructs a ppmcolormask command string. The application improperly uses unsanitized user-controlled text object fill-color values directly within a shell command string.\nThe application relies on child_process.exec, which spawns a shell process to execute the provided command string. Because the shell interprets metacharacters (such as backticks, semicolons, or pipe operators), an attacker can escape the intended command context.\nThe attack flow begins when an attacker modifies the fill-color property of a text object within a Penpot file to include malicious shell syntax. This can be achieved by an authenticated user editing a file or by utilizing a public share link to a crafted document.\nWhen the SVG export functionality is invoked—either by a user or automatically upon access to a shared link—the exporter service processes the malicious metadata. The vulnerable logic injects the attacker's payload into the ppmcolormask execution sequence.\nUpon execution of child_process.exec, the shell parses the concatenated string, executing both the legitimate ppmcolormask command and the attacker's injected code. This behavior facilitates the execution of arbitrary operating system commands.\nThe exploitation does not require advanced memory corruption techniques, as it relies on the logical failure of input sanitization during inter-process communication.\nThe post-exploitation impact is severe, granting the attacker the same execution context as the exporter process. This allows for the execution of arbitrary payloads, modification of environment variables, access to internal network resources, and potentially full persistent control over the server environment.\nThe issue is confirmed to exist in all versions of Penpot prior to 2.18.0."
}
CVE-2026-105691: Penpot SVG Export Command Injection (CRITICAL Severity, CVSS: 9.9) | Sceawere