CVE-2026-105691: Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through childprocess.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.18.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any user who can edit a Penpot file can place shell metacharacters in a text object's legacy fill-color value. An attacker can also cause the export through a valid public share link to a malicious file.
What action triggers command execution?
Command execution occurs when the malicious file is exported as SVG. The injected command runs with the privileges of the exporter service.
Which versions are affected?
Penpot versions prior to 2.18.0 are affected. The issue is fixed in version 2.18.0.