CVE-2026-105692: Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Penpotto a version that resolves this vulnerability.Fixed in 2.18.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any user with edit permission on the affected file can exploit it. The user must also know the UUID of a share link created by another user for that file.
What is the impact of successful exploitation?
An attacker can delete another user's share link and revoke access for external reviewers using that link. The issue affects availability of shared access and permits unauthorized modification of share-link state.
Are default deployments affected?
The issue is reachable through the delete-share-link RPC when a user has edit access to a file. The provided information does not identify any additional configuration prerequisite.
What versions should be remediated?
Versions prior to 2.18.0 are affected. Upgrade to Penpot 2.18.0, which includes the fix.