Sceawere
Vulnerability Detail
CVE-2026-105695UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Penpot Insecure Session Handling Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 1h ago
- Vendor
- penpot
- Product
- penpot
- Attack Type
- CWE-862: Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-05T20:17:20.017Z",
"pubdate": "2026-10-05T20:17:20.017Z",
"executiveSummary": "A broken access control vulnerability exists in Penpot prior to version 2.18.0, stemming from improper validation logic within the file upload process.\nThe vulnerability allows an authenticated attacker to perform unauthorized file assembly by referencing a target user's active upload session UUID.\nThe primary risk involves unauthorized data disclosure, as an attacker can cause a victim's uploaded data fragments to be assembled into the attacker's own workspace.\nAffected systems include all instances of Penpot running versions prior to 2.18.0.\nSuccessful exploitation requires the attacker to possess a valid authentication token for the platform and to discover or obtain a legitimate, pending session UUID belonging to another user.\nThis flaw effectively bypasses intended multi-tenant isolation, leading to potential sensitive information leakage and the disruption of the victim's upload workflow through the premature deletion of their pending sessions.",
"technicalDetails": "The vulnerability resides in the discrepancy between access control implementations for the 'assemble-chunks' and 'upload-chunk' functions within the Penpot backend.\nIn the affected versions, the 'upload-chunk' function correctly enforces data isolation by verifying that the session ID belongs to the profile of the authenticated user. However, the 'assemble-chunks' function fails to perform this scoping check, accepting any provided session UUID without validating ownership.\nThe exploitation flow begins when an attacker identifies or obtains a live, completed upload-session UUID associated with another user's session. Since the 'assemble-chunks' endpoint lacks server-side authorization checks against the authenticated user's profile, the attacker can submit an arbitrary request containing the victim's UUID.\nUpon receiving this request, the system erroneously processes the assembly of the victim's chunks into the attacker's context. This enables the attacker to treat the victim's data as their own file, team font, or project import. Consequently, the uploaded bytes are disclosed to the attacker, and the system performs a cleanup action that deletes the victim's original pending session, resulting in a denial-of-service for the victim's upload operation.\nThis represents a significant failure in the application's object-level authorization (BOLA) logic. By not coupling the session assembly process to the session creator's security context, the application fails to maintain strict boundaries between user sessions. The attack is achievable by any authenticated user within the environment, requiring no administrative privileges. Because the application exposes the session UUIDs, an attacker capable of intercepting or guessing these identifiers can bypass logical access controls, leading to total compromise of the data contained within the targeted upload session."
}