CVE-2026-105692

Source
https://cve.org/CVERecord?id=CVE-2026-105692
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105692.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105692
Aliases
  • GHSA-8257-pm4f-cfhq
Published
2026-10-05T19:55:36Z
Modified
2026-10-08T02:50:00Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create
Details

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284",
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105692.json"
}
References

Affected packages

Git / github.com/penpot/penpot

Affected ranges

Type
GIT
Repo
https://github.com/penpot/penpot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.18.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.0
0.1.0
1.*
1.0.0-alpha
1.1.0-alpha
1.14.0-beta
1.14.1-beta
1.2.0-alpha
1.3.0-alpha
1.4.0-alpha
1.4.0-dev
1.4.1-alpha
1.5.0-alpha
1.5.1-alpha
1.5.2-alpha
1.5.3-alpha
1.5.4-alpha
1.6.0-alpha
1.6.1-alpha
1.6.2-alpha
1.6.3-alpha
1.6.4-alpha
1.6.5-alpha
1.7.0-alpha
1.7.1-alpha
1.7.2-alpha
1.7.3-alpha
1.7.4-alpha
1.8.0-alpha
1.8.1-alpha
1.8.2-alpha
1.9.0-alpha
2.*
2.10.0-RC1
2.14.0-RC1
2.14.0-RC2
2.14.0-RC3
2.14.0-RC4
2.15.0-RC1
2.16.0
2.16.0-RC1
2.16.0-RC11
2.16.0-RC13
2.16.0-RC2
2.16.0-RC3
2.16.0-RC4
2.16.0-RC5
2.16.0-RC6
2.16.0-RC7
2.16.0-RC8
2.16.0-RC9
2.16.1-RC2
2.17.0
2.17.0-RC1
2.17.0-RC3
2.17.0-RC4
2.17.0-RC5
2.17.0-RC6
2.17.1-RC1
2.17.1-RC2
2.17.1-RC3
2.17.1-RC4
2.17.1-RC5
2.18.0-RC1
2.5.0-DEV
2.5.0-RC1
2.6.0-RC1
2.7.0-RC1
Other
pre-lazy-loading

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105692.json"