Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-17613 1 Penpot 1 Penpot 2026-08-05 7.5 High
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.