CVE-2026-105690: Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access

Published Oct 5, 2026
·
Updated

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.

Affected Software

1 affected component
Penpot Penpot<2.18.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Penpot to a version that resolves this vulnerability.

    Fixed in 2.18.0

Event History

Oct 5, 2026
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Penpot deployments running versions before 2.18.0 are affected. A user is at risk if an attacker has previously captured that user's valid session token.

2

What must an attacker do to exploit the issue?

The attacker needs a previously captured valid Penpot session token. They can use it to make authenticated requests as the victim even after the victim logs out, until the token naturally expires.

3

Does logging out protect a user whose token may have been captured?

No. On affected versions, logout clears the browser cookie but does not revoke the associated server-side session, so the captured token remains valid.

4

What is the remediation?

Upgrade Penpot to version 2.18.0, which fixes server-side session invalidation on logout.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203