CVE-2026-105689: Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Penpotto a version that resolves this vulnerability.Fixed in 2.18.0
Event History
Frequently Asked Questions
Which deployments are most exposed to this issue?
Penpot deployments prior to 2.18.0 that use a NAT64 gateway are directly exploitable. Deployments may also be exposed when an attacker can control a DNS AAAA record that resolves to a crafted IPv6 transition address.
What level of attacker control is needed?
An attacker needs control of a media import URL, or administrator-level control of a webhook URL. They can use NAT64, 6to4, or Teredo IPv6 transition addresses that embed an IPv4 loopback, link-local, private, or cloud-metadata target.
What can an attacker obtain through each affected feature?
Media import can disclose the bodies of responses retrieved from internal targets. Webhook delivery can reveal response status, enabling network probing as a side channel.
What version fixes the issue?
Upgrade Penpot to version 2.18.0, which fixes the SSRF guard bypass.