CVE-2026-105690: Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Penpotto a version that resolves this vulnerability.Fixed in 2.18.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Penpot deployments running versions before 2.18.0 are affected. A user is at risk if an attacker has previously captured that user's valid session token.
What must an attacker do to exploit the issue?
The attacker needs a previously captured valid Penpot session token. They can use it to make authenticated requests as the victim even after the victim logs out, until the token naturally expires.
Does logging out protect a user whose token may have been captured?
No. On affected versions, logout clears the browser cookie but does not revoke the associated server-side session, so the captured token remains valid.
What is the remediation?
Upgrade Penpot to version 2.18.0, which fixes server-side session invalidation on logout.