CVE-2026-105693: Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Penpotto a version that resolves this vulnerability.Fixed in 2.18.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Penpot deployments running versions before 2.18.0 are affected where files are shared using scoped share links. A person who holds a restrictive share link for a file can potentially access data from pages outside that link's intended scope.
What does an attacker need to exploit it?
The attacker needs a valid share-link token for the affected file, including a restrictive or page-scoped link. No authenticated Penpot account or user interaction is required.
What information can be disclosed?
The vulnerable RPC can return every share-link row for the file, including other links' secret IDs, page scopes, comment permissions, and inspection permissions. More permissive disclosed tokens can then be replayed to obtain page data not available through the original link.
What is the remediation?
Upgrade Penpot to version 2.18.0, which fixes the issue. If upgrading cannot happen immediately, limit distribution of share links for affected files, particularly links scoped to different pages or with differing permissions.