PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45806 penpot CVE debrief

Penpot, an open-source design tool for design and code collaboration, had a vulnerability in versions before 2.15.0 that allowed authenticated file editors to access internal-only endpoints through the remote image import feature. This issue was due to insufficient destination filtering in the shared HTTP client. Users of Penpot, especially those with authenticated access to file editing features, should be aware of this vulnerability and ensure they are running version 2.15.0 or later to mitigate the risk. The CVE record was published on 2026-07-15T16:16:45.927Z and last modified on 2026-07-20T16:17:00.887Z. The NVD entry is currently Deferred.

Vendor
penpot
Product
Unknown
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-15
Original CVE updated
2026-07-20
Advisory published
2026-07-15
Advisory updated
2026-07-20

Who should care

Users of Penpot, especially those with authenticated access to file editing features, should be aware of this vulnerability and ensure they are running version 2.15.0 or later to mitigate the risk. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of this vulnerability on their environments and take appropriate action.

Technical summary

The vulnerability in Penpot before version 2.15.0 allows an authenticated file editor to access internal-only endpoints through the remote image import feature. This is due to the lack of destination filtering in the shared HTTP client used by the media/download-image function. The issue arises from the user-controlled URL being passed from the frontend into the backend RPC method without proper filtering, enabling potential unauthorized access to internal endpoints.

Defensive priority

High

Recommended defensive actions

  • Upgrade to Penpot version 2.15.0 or later
  • Restrict access to file editing features to trusted users
  • Monitor for suspicious activity related to remote image imports
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-15T16:16:45.927Z and last modified on 2026-07-20T16:17:00.887Z. The NVD entry is currently Deferred. This vulnerability affects Penpot, an open-source design tool for design and code collaboration. The remote image import feature in Penpot versions before 2.15.0 allows an authenticated file editor to access internal-only endpoints due to the lack of destination filtering in the shared HTTP client used by the media/download-image function. Users should verify their current version and update to 2.15.0 or later to mitigate this risk. Additional verification steps include reviewing access controls for file editing features and monitoring for suspicious activity related to remote image imports.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T16:16:45.927Z and has not been modified since then. The NVD entry is currently Deferred.