Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
CVE-2026-17613
CVE-2026-17613
Description
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.