CVE-2026-100868

Source
https://cve.org/CVERecord?id=CVE-2026-100868
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100868.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100868
Related
Published
2026-09-27T13:09:53Z
Modified
2026-10-02T03:30:48Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge
Details

Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-1327"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100868.json"
}
References

Affected packages

Git / github.com/penpot/penpot

Affected ranges

Type
GIT
Repo
https://github.com/penpot/penpot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.18.0"
        },
        {
            "last_affected":  "2.15.4"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

0.*
0.0.0
0.1.0
1.*
1.0.0-alpha
1.1.0-alpha
1.14.0-beta
1.14.1-beta
1.2.0-alpha
1.3.0-alpha
1.4.0-alpha
1.4.0-dev
1.4.1-alpha
1.5.0-alpha
1.5.1-alpha
1.5.2-alpha
1.5.3-alpha
1.5.4-alpha
1.6.0-alpha
1.6.1-alpha
1.6.2-alpha
1.6.3-alpha
1.6.4-alpha
1.6.5-alpha
1.7.0-alpha
1.7.1-alpha
1.7.2-alpha
1.7.3-alpha
1.7.4-alpha
1.8.0-alpha
1.8.1-alpha
1.8.2-alpha
1.9.0-alpha
2.*
2.10.0-RC1
2.14.0-RC1
2.14.0-RC2
2.14.0-RC3
2.14.0-RC4
2.15.0-RC1
2.16.0
2.16.0-RC1
2.16.0-RC11
2.16.0-RC13
2.16.0-RC2
2.16.0-RC3
2.16.0-RC4
2.16.0-RC5
2.16.0-RC6
2.16.0-RC7
2.16.0-RC8
2.16.0-RC9
2.16.1-RC2
2.17.0
2.17.0-RC1
2.17.0-RC3
2.17.0-RC4
2.17.0-RC5
2.17.0-RC6
2.17.1-RC1
2.17.1-RC2
2.17.1-RC3
2.17.1-RC4
2.17.1-RC5
2.18.0-RC1
2.18.0-RC2
2.18.0-RC3
2.18.0-RC4
2.18.0-RC6
2.18.0-RC7
2.5.0-DEV
2.5.0-RC1
2.6.0-RC1
2.7.0-RC1
Other
pre-lazy-loading

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100868.json"