CVE-2026-105693: Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle

Published Oct 5, 2026
·
Updated

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.

Affected Software

1 affected component
Penpot Penpot<2.18.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Penpot to a version that resolves this vulnerability.

    Fixed in 2.18.0

Event History

Oct 5, 2026
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Penpot deployments running versions before 2.18.0 are affected where files are shared using scoped share links. A person who holds a restrictive share link for a file can potentially access data from pages outside that link's intended scope.

2

What does an attacker need to exploit it?

The attacker needs a valid share-link token for the affected file, including a restrictive or page-scoped link. No authenticated Penpot account or user interaction is required.

3

What information can be disclosed?

The vulnerable RPC can return every share-link row for the file, including other links' secret IDs, page scopes, comment permissions, and inspection permissions. More permissive disclosed tokens can then be replayed to obtain page data not available through the original link.

4

What is the remediation?

Upgrade Penpot to version 2.18.0, which fixes the issue. If upgrading cannot happen immediately, limit distribution of share links for affected files, particularly links scoped to different pages or with differing permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203